CVE-2021-21083 HIGH

CVE-2021-21083: Adobe Experience Manager broken access control in DSRPReindexServlet could lead to denial-of-service

Vendor Adobe
Product Experience Manager
Weakness CWE-284
Published June 28, 2021
Last update September 16, 2024

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by an Improper Access Control vulnerability. An unauthenticated attacker could leverage this vulnerability to cause an application denial-of-service in the context of the current user.

Key dates

02Disclosure timeline

June 28, 2021 CVE published
September 16, 2024 Record updated