logo

CVE-2016-0956 org.apache.sling:org.apache.sling.servlets.post

Package

Manager: maven
Name: org.apache.sling:org.apache.sling.servlets.post
Vulnerable Version: >=0 <2.3.8

Severity

Level: High

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.13277 pctl0.93909

Details

Exposure of Sensitive Information to an Unauthorized Actor in Apache Sling Servlets Post The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.

Metadata

Created: 2022-05-14T02:47:05Z
Modified: 2022-07-06T20:05:20Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m27m-628v-xxp2/GHSA-m27m-628v-xxp2.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-m27m-628v-xxp2
Finding: F017
Auto approve: 1