One of our security team member was successful in accessing critical AEM nodes by bypassing dispatcher using this special encoding technique that uses ASCII code for the } character (Example: * /.%7D./.%7D./.%7D./.%7D./.%7D./)
To bypass authentication they downloaded an auth certificate using this vulnerability.
We were able to address this by adding few entries in dispatcher filters.
But we are not able to understand why ' } ' worked as valid bypass?