What Windows Vulnerabilities does AEM Forms 6.5.0-0044 fixes? | Community
Skip to main content
coldwarsoldier
Level 2
June 10, 2022
Solved

What Windows Vulnerabilities does AEM Forms 6.5.0-0044 fixes?

  • June 10, 2022
  • 2 replies
  • 1024 views

More specifically, I need to know if AEM Forms 6.5.0-0044 fixes the vulnerabilities below.  Thank you.

 

Apache Shiro < 1.8.0 Authentication Bypass

Apache POI < 3.17 Multiple DoS Vulnerabilities

This post is no longer active and is closed to new replies. Need help? Start a new post to ask your question.
Best answer by Pulkit_Jain_

@coldwarsoldier 

AEM Forms JEE uses apache-poi 3.17 to address CVE-2017-12626.

I don't see any reference to Apache Shiro i.e Authentication Bypass to address CVE-2021-41303 in the archives so don't think this was reported previously. May have to check if this library is used by any module in AEM Forms JEE or not. 

Please raise a support ticket to get the impact of this vulnerability accessed. Also, a vulnerability scan report will help.

2 replies

Pulkit_Jain_
Adobe Employee
Pulkit_Jain_Adobe EmployeeAccepted solution
Adobe Employee
June 10, 2022

@coldwarsoldier 

AEM Forms JEE uses apache-poi 3.17 to address CVE-2017-12626.

I don't see any reference to Apache Shiro i.e Authentication Bypass to address CVE-2021-41303 in the archives so don't think this was reported previously. May have to check if this library is used by any module in AEM Forms JEE or not. 

Please raise a support ticket to get the impact of this vulnerability accessed. Also, a vulnerability scan report will help.

Mayank_Gandhi
Adobe Employee
Adobe Employee
June 10, 2022

@coldwarsoldier Are those being flagged in the security scan? I doubt seeing them in forms.

coldwarsoldier
Level 2
June 13, 2022

Yes, these vulnerabilities were found during a scan 

Mayank_Gandhi
Adobe Employee
Adobe Employee
June 14, 2022

@coldwarsoldier In that case you need to log a support case with the security scan report and the team will check further.