Vulnerability CVE-2023-22271


Published: 2023-03-22

Description:
Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for Passwords vulnerability that can lead to a security feature bypass. A low-privileged attacker can exploit this in order to decrypt a user's password. The attack complexity is high since a successful exploitation requires to already have in possession this encrypted secret.

Type:

CWE-261

(Weak Cryptography for Passwords)

 References:
https://helpx.adobe.com/security/products/experience-manager/apsb23-18.html

Copyright 2024, cxsecurity.com

 

Back to Top