Description
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.
In plain language
AI Worth attentionApache Sling’s Post component can expose sensitive information in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, so affected businesses should arrange the vendor fix soon.
Remote information disclosure in Apache Sling Servlets Post 2.3.6 (CWE-200) through unspecified vectors, affecting deployments used by Adobe Experience Manager.
What to do now
- Ask your IT provider to check whether you run Adobe Experience Manager 5.6.1, 6.0.0, or 6.1.0 with the Apache Sling Post component.
- Apply Adobe’s security update for your Experience Manager release, or upgrade
org.apache.sling:org.apache.sling.servlets.postto version 2.3.8 or later where that package is managed directly. - Until updated, limit public access to the affected system and review its web-access logs for unexpected requests to Sling Post endpoints.
mvn dependency:upgrade -Dartifact=org.apache.sling:org.apache.sling.servlets.post:2.3.8CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-0956 and every CVE in our database. Create a free account — no credit card required.
Create Free Account