CVE-2022-42351 MEDIUM

CVE-2022-42351: AEM Incorrect Authorization Security feature bypass

Vendor Adobe
Product Experience Manager
Weakness CWE-863 · Incorrect authorization
Published December 19, 2022
Last update April 23, 2025

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Adobe Experience Manager version 6.5.14 (and earlier) is affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to disclose low level confidentiality information. Exploitation of this issue does not require user interaction.

Key dates

02Disclosure timeline

December 19, 2022 CVE published
April 23, 2025 Record updated