VDB
CVE-2021-42725
CVE-2021-42725
PUBLISHED
CVSS 5.300000190734863 MEDIUM
Adobe has released updates for Adobe Experience Manager (AEM). These updates resolve vulnerabilities rated critical and Important. Successful exploitation of these vulnerabilities could result in arbitrary code execution. Vulnerability: Improper Access Control (CWE-284) Impact: Security feature bypass Severity: Important CVSS: 5.3 CWE: CWE-284
EPSS 1.90% · 78.2th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
1.90%
78.2th percentile
Timeline
- Sep 14, 2021 CVE Published
- Nov 17, 2021 EPSS Score
- Nov 18, 2021 EPSS Score
- Jan 11, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 17, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jun 27, 2022 EPSS Score
- Aug 22, 2022 EPSS Score
- Dec 11, 2022 EPSS Score
- Feb 5, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://helpx.adobe.com/security/products/experience-manager/apsb21-82.html advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42725 advisory
- https://experienceleague.adobe.com/docs/experience-manager-cloud-service/release-notes/release-notes/release-notes-current.html?lang=en#release-notes patch