CVE-2021-40722

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
13/01/2022
Last modified:
19/01/2022

Description

AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:* 6.5.10.0 (including)
cpe:2.3:a:adobe:experience_manager_cloud_service:-:*:*:*:*:*:*:*