CVE-2016-0956 – org.apache.sling:org.apache.sling.servlets.post
Package
Manager: maven
Name: org.apache.sling:org.apache.sling.servlets.post
Vulnerable Version: >=0 <2.3.8
Severity
Level: High
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.13277 pctl0.93909
Details
Exposure of Sensitive Information to an Unauthorized Actor in Apache Sling Servlets Post The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.
Metadata
Created: 2022-05-14T02:47:05Z
Modified: 2022-07-06T20:05:20Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m27m-628v-xxp2/GHSA-m27m-628v-xxp2.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-m27m-628v-xxp2
Finding: F017
Auto approve: 1