ID

VAR-201602-0319


CVE

CVE-2016-0957


TITLE

Adobe Experience Manager of Dispatcher Vulnerability in which dispatcher rules could be bypassed

Trust: 0.8

sources: JVNDB: JVNDB-2016-001468

DESCRIPTION

Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors. Adobe Experience Manager (AEM) is a set of content management solutions from Adobe (Adobe) that can be used to build websites, mobile applications and forms. The solution supports mobile content management, marketing and sales campaign management, and multi-site management. Dispatcher is one of the tools that keeps AEM cached or load balanced. There is a security vulnerability in AE M's Dispatcher, which is caused by the program not implementing the URL filter correctly. The following versions are affected: AEM version 5.6.1, version 6.0.0, version 6.1.0, Dispatcher versions prior to 4.1.5

Trust: 1.8

sources: NVD: CVE-2016-0957 // JVNDB: JVNDB-2016-001468 // VULHUB: VHN-88467 // VULMON: CVE-2016-0957

AFFECTED PRODUCTS

vendor:adobemodel:experience managerscope:eqversion:6.0.0

Trust: 1.6

vendor:adobemodel:experience managerscope:eqversion:6.1.0

Trust: 1.6

vendor:adobemodel:experience managerscope:eqversion:5.6.1

Trust: 1.6

vendor:adobemodel:dispatcherscope:lteversion:4.1.4

Trust: 1.0

vendor:adobemodel:experience managerscope:eqversion:5.6.1 (windows/unix/linux/os x)

Trust: 0.8

vendor:adobemodel:experience managerscope:eqversion:6.0.0 (windows/unix/linux/os x)

Trust: 0.8

vendor:adobemodel:experience managerscope:eqversion:6.1.0 (windows/unix/linux/os x)

Trust: 0.8

vendor:adobemodel:dispatcherscope:eqversion:4.1.4

Trust: 0.6

sources: JVNDB: JVNDB-2016-001468 // CNNVD: CNNVD-201602-220 // NVD: CVE-2016-0957

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-0957
value: HIGH

Trust: 1.0

NVD: CVE-2016-0957
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201602-220
value: HIGH

Trust: 0.6

VULHUB: VHN-88467
value: HIGH

Trust: 0.1

VULMON: CVE-2016-0957
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2016-0957
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-88467
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-0957
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.0

sources: VULHUB: VHN-88467 // VULMON: CVE-2016-0957 // JVNDB: JVNDB-2016-001468 // CNNVD: CNNVD-201602-220 // NVD: CVE-2016-0957

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2016-0957

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201602-220

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201602-220

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-001468

PATCH

title:APSB16-05url:http://helpx.adobe.com/security/products/experience-manager/apsb16-05.html

Trust: 0.8

title:APSB16-05url:http://helpx.adobe.com/jp/security/products/experience-manager/apsb16-05.html

Trust: 0.8

title:Adobe Experience Manager Dispatcher Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=60162

Trust: 0.6

title:CVE-Studyurl:https://github.com/thdusdl1219/CVE-Study

Trust: 0.1

sources: VULMON: CVE-2016-0957 // JVNDB: JVNDB-2016-001468 // CNNVD: CNNVD-201602-220

EXTERNAL IDS

db:NVDid:CVE-2016-0957

Trust: 2.6

db:JVNDBid:JVNDB-2016-001468

Trust: 0.8

db:CNNVDid:CNNVD-201602-220

Trust: 0.7

db:VULHUBid:VHN-88467

Trust: 0.1

db:BIDid:83123

Trust: 0.1

db:VULMONid:CVE-2016-0957

Trust: 0.1

sources: VULHUB: VHN-88467 // VULMON: CVE-2016-0957 // JVNDB: JVNDB-2016-001468 // CNNVD: CNNVD-201602-220 // NVD: CVE-2016-0957

REFERENCES

url:https://helpx.adobe.com/security/products/experience-manager/apsb16-05.html

Trust: 1.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-0957

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-0957

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://www.securityfocus.com/bid/83123

Trust: 0.1

url:https://github.com/thdusdl1219/cve-study

Trust: 0.1

sources: VULHUB: VHN-88467 // VULMON: CVE-2016-0957 // JVNDB: JVNDB-2016-001468 // CNNVD: CNNVD-201602-220 // NVD: CVE-2016-0957

SOURCES

db:VULHUBid:VHN-88467
db:VULMONid:CVE-2016-0957
db:JVNDBid:JVNDB-2016-001468
db:CNNVDid:CNNVD-201602-220
db:NVDid:CVE-2016-0957

LAST UPDATE DATE

2024-08-14T15:29:30.964000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-88467date:2016-02-25T00:00:00
db:VULMONid:CVE-2016-0957date:2016-02-25T00:00:00
db:JVNDBid:JVNDB-2016-001468date:2016-02-23T00:00:00
db:CNNVDid:CNNVD-201602-220date:2016-02-15T00:00:00
db:NVDid:CVE-2016-0957date:2016-02-25T19:44:38.713

SOURCES RELEASE DATE

db:VULHUBid:VHN-88467date:2016-02-10T00:00:00
db:VULMONid:CVE-2016-0957date:2016-02-10T00:00:00
db:JVNDBid:JVNDB-2016-001468date:2016-02-23T00:00:00
db:CNNVDid:CNNVD-201602-220date:2016-02-15T00:00:00
db:NVDid:CVE-2016-0957date:2016-02-10T20:59:09.967