Embedded PDF binary metadata (XMP/DocumentInfo) persists after download despite removing all AEM-managed metadata | Community
Skip to main content
Level 2
April 23, 2026
Question

Embedded PDF binary metadata (XMP/DocumentInfo) persists after download despite removing all AEM-managed metadata

  • April 23, 2026
  • 0 replies
  • 4 views

A third-party penetration test flagged that PDF files downloaded from our AEM publish instance contain embedded metadata revealing software version information (e.g., Adobe InDesign 19.5, Adobe PDF Library 17.0, Adobe XMP Core 9.1). The security team requires this metadata to be stripped before the file is served to end users.

We are requesting Adobe's official confirmation that AEM as a Cloud Service does not modify or strip metadata embedded within the binary content of uploaded DAM assets, and guidance on the recommended approach.

 

What We Tried 

1. Removed XMP metadata properties from the JCR metadata node

2. Deleted the entire metadata node