CVE-2021-21009 HIGH

CVE-2021-21009: Server-side request forgery (SSRF) in Campaign Classic could lead to sensitive information disclosure

Vendor Adobe
Product Campaign
Weakness CWE-918 · SSRF
Published January 13, 2021
Last update April 23, 2025

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitation could allow an attacker to use the Campaign instance to issue unauthorized requests to internal or external resources.

Key dates

02Disclosure timeline

January 13, 2021 CVE published
April 23, 2025 Record updated