Adobe Security Bulletin

Security updates available for Adobe Experience Manager | APSB18-10

Bulletin ID

Date Published

Priority

APSB18-10

April 10, 2018

3

Summary

Adobe has released security updates for Adobe Experience Manager. These updates resolve a stored cross-site scripting vulnerability (CVE-2018-4929) rated moderate, and two cross-site scripting vulnerabilities (CVE-2018-4930 and CVE-2018-4931) rated important

Affected product versions

Product

Version

Platform

Adobe Experience Manager

6.3

6.2

6.1

6.0

All

Solution

Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:

Product Version Platform Priority Availability
Adobe Experience Manager
6.3
All 3 Release note
6.2 All 3 Release note
6.1 All 3 Release note
6.0 All 3 Release note

Please contact Adobe customer care for assistance with earlier AEM versions.

Vulnerability details

Vulnerability Category

Vulnerability Impact

Severity

CVE Numbers

Affected Version

Download Package

Stored cross-site scripting

Sensitive Information disclosure

Moderate

CVE-2018-4929

AEM 6.2 and earlier

Cross-site scripting

Sensitive Information Disclosure

Important

CVE-2018-4930

AEM 6.3 and earlier

Stored cross-site scripting

Sensitive Information Disclosure

Important

CVE-2018-4931

AEM 6.1 and earlier

Note:

The packages listed in the table above are the minimum fix packs to address the listed vulnerability.  For the latest versions, please see the release notes links referenced above.

Acknowledgments

Adobe would like to thank the following individuals and organizations for reporting the relevant issues and for working with Adobe to help protect our customers:  

  • Frans Rosen of Detectify Labs (CVE-2018-4930)
  • Nagamarimuthu of Cognizant Technology Solutions - Enterprise Risk & Security Solutions (CVE-2018-4931)

 Adobe

Get help faster and easier

New user?