SB20240312326 - Multiple vulnerabilities in Adobe Experience Manager
Published: March 12, 2024 Updated: June 12, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 47 secuirty vulnerabilities.
1) Stored cross-site scripting (CVE-ID: CVE-2024-26107)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
2) Stored cross-site scripting (CVE-ID: CVE-2024-26073)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
3) Stored cross-site scripting (CVE-ID: CVE-2024-26080)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
4) Stored cross-site scripting (CVE-ID: CVE-2024-26094)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
5) Stored cross-site scripting (CVE-ID: CVE-2024-26096)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
6) Stored cross-site scripting (CVE-ID: CVE-2024-26102)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
7) Stored cross-site scripting (CVE-ID: CVE-2024-26103)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
8) Stored cross-site scripting (CVE-ID: CVE-2024-26104)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
9) Stored cross-site scripting (CVE-ID: CVE-2024-26105)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
10) Stored cross-site scripting (CVE-ID: CVE-2024-26106)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
11) Stored cross-site scripting (CVE-ID: CVE-2024-26118)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
12) Stored cross-site scripting (CVE-ID: CVE-2024-26067)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
13) Improper access control (CVE-ID: CVE-2024-26119)
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the application.
14) Stored cross-site scripting (CVE-ID: CVE-2024-26120)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
15) Stored cross-site scripting (CVE-ID: CVE-2024-26124)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
16) Stored cross-site scripting (CVE-ID: CVE-2024-26125)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
17) Stored cross-site scripting (CVE-ID: CVE-2024-20760)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
18) Stored cross-site scripting (CVE-ID: CVE-2024-20768)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
19) Security features bypass (CVE-ID: CVE-2024-26126)
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to insufficient input validation. A remote user can bypass certain security restrictions.
20) Security features bypass (CVE-ID: CVE-2024-26127)
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to insufficient input validation. A remote user can bypass certain security restrictions.
21) Stored cross-site scripting (CVE-ID: CVE-2024-26051)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
22) Stored cross-site scripting (CVE-ID: CVE-2024-26069)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
23) Stored cross-site scripting (CVE-ID: CVE-2024-26065)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
24) Stored cross-site scripting (CVE-ID: CVE-2024-26028)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
25) Stored cross-site scripting (CVE-ID: CVE-2024-26042)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
26) Stored cross-site scripting (CVE-ID: CVE-2024-26030)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
27) Stored cross-site scripting (CVE-ID: CVE-2024-26031)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
28) Stored cross-site scripting (CVE-ID: CVE-2024-26032)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
29) Stored cross-site scripting (CVE-ID: CVE-2024-26033)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
30) Stored cross-site scripting (CVE-ID: CVE-2024-26034)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
31) Stored cross-site scripting (CVE-ID: CVE-2024-26035)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
32) Stored cross-site scripting (CVE-ID: CVE-2024-26038)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
33) Stored cross-site scripting (CVE-ID: CVE-2024-26040)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
34) Stored cross-site scripting (CVE-ID: CVE-2024-26041)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
35) Stored cross-site scripting (CVE-ID: CVE-2024-26043)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
36) Stored cross-site scripting (CVE-ID: CVE-2024-26064)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
37) Stored cross-site scripting (CVE-ID: CVE-2024-26044)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
38) Stored cross-site scripting (CVE-ID: CVE-2024-26045)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
39) Stored cross-site scripting (CVE-ID: CVE-2024-20799)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
40) Stored cross-site scripting (CVE-ID: CVE-2024-26050)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
41) Stored cross-site scripting (CVE-ID: CVE-2024-26052)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
42) Stored cross-site scripting (CVE-ID: CVE-2024-26056)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
43) Stored cross-site scripting (CVE-ID: CVE-2024-26059)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
44) Stored cross-site scripting (CVE-ID: CVE-2024-26061)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
45) Stored cross-site scripting (CVE-ID: CVE-2024-26062)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
46) Information disclosure (CVE-ID: CVE-2024-26063)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to sensitive information on the system.
47) Stored cross-site scripting (CVE-ID: CVE-2024-20800)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can permanently inect and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Remediation
Install update from vendor's website.