Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate server-side requests and bypass security controls allowing unauthorized read access.
2025-09-09T17:15:58.663
2025-09-12T14:21:46.463
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | adobe | experience_manager | ≤ 6.5.23.0 | Yes |
| Application | adobe | experience_manager | ≤ 2025.8.0 | Yes |
| Application | adobe | experience_manager | 6.5 | Yes |
| Application | adobe | experience_manager | 6.5 | Yes |