Lucene search

K
nvd[email protected]NVD:CVE-2020-9736
HistorySep 10, 2020 - 5:15 p.m.

CVE-2020-9736

2020-09-1017:15:40
CWE-79
web.nvd.nist.gov
6
aem
stored xss
content repository development environment
malicious scripts
browser execution

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

25.3%

AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when browsing to the page containing the vulnerable field.

Affected configurations

Nvd
Node
adobeexperience_managerRange6.3.0.0–6.3.3.8
OR
adobeexperience_managerRange6.4.0.0–6.4.8.1
OR
adobeexperience_managerRange6.5.0.0–6.5.5.0
OR
adobeexperience_managerMatch6.2.0.0sp1
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp1
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp10
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp11
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp12.1
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp13
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp14
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp15
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp16
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp17
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp18
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp19
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp2
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp20
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp3
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp4
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp5
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp6
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp7
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp8
OR
adobeexperience_managerMatch6.2.0.0sp1-cfp9
VendorProductVersionCPE
adobeexperience_manager*cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:*
adobeexperience_manager6.2.0.0cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1:*:*:*:*:*:*
adobeexperience_manager6.2.0.0cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp1:*:*:*:*:*:*
adobeexperience_manager6.2.0.0cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp10:*:*:*:*:*:*
adobeexperience_manager6.2.0.0cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp11:*:*:*:*:*:*
adobeexperience_manager6.2.0.0cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp12.1:*:*:*:*:*:*
adobeexperience_manager6.2.0.0cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp13:*:*:*:*:*:*
adobeexperience_manager6.2.0.0cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp14:*:*:*:*:*:*
adobeexperience_manager6.2.0.0cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp15:*:*:*:*:*:*
adobeexperience_manager6.2.0.0cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp16:*:*:*:*:*:*
Rows per page:
1-10 of 221

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

25.3%

Related for NVD:CVE-2020-9736