Back

MEDIUM

AEM Weak Cryptography for Passwords Security feature bypass

Published Mar 22, 2023

Description

Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for Passwords vulnerability that can lead to a security feature bypass. A low-privileged attacker can exploit this in order to decrypt a user's password. The attack complexity is high since a successful exploitation requires to already have in possession this encrypted secret.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Mar 22, 2023
Updated Mar 5, 2025
Reserved Dec 19, 2022
CISA Vulnrichment
Updated Mar 5, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner adobe
Published Mar 22, 2023
Updated Mar 5, 2025
Exploited since n/a
EUVD-2023-26435