Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
affected
Any version
affected
Description
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.
Problem types
Deserialization of Untrusted Data (CWE-502)
Product status
Any version
References
helpx.adobe.com/security/products/aem-forms/apsb25-67.html