Hi Team,
Facing issue with below vulnerability in AEM server -
Any idea which service pack / hotfix this vulnerability got fixed ?
My current AEM version is AEM 6.5.21
This jar is embedded as part of com.adobe.cq.dam.cq-scene7-imaging
Spring Framework Path Traversal Vulnerability
Vulnerability Result:
<server-path>/felix/bundle388/version0.1/bundle.jar-embedded/spring-webmvc-5.3.28.jar
<server-path>/felix/bundle388/version0.1/bundle.jar-embedded/spring-webmvc-5.3.28.jar
fixed in 5.3.40, 6.0.24, 6.1.13
Any Suggestions are welcome
Thanks
Solved! Go to Solution.
Views
Replies
Total Likes
Hello @Prath_AEM ,
- The CVE associated with this vulnerability is CVE-2024-38856, fixed by Spring in 5.3.40 and later.
- From the internal AEM release notes and patch tracking (as per Adobe’s vulnerability fix cadence):
spring-* libraries embedded in several DAM bundles.
Hi @Prath_AEM
Can you upgrade to the latest version 6.5.23 and give it a try? This looks like is fixed in the latest version.
Views
Replies
Total Likes
Hello @Prath_AEM ,
- The CVE associated with this vulnerability is CVE-2024-38856, fixed by Spring in 5.3.40 and later.
- From the internal AEM release notes and patch tracking (as per Adobe’s vulnerability fix cadence):
spring-* libraries embedded in several DAM bundles.
Hello @Prath_AEM ,
If the answer resolves your query, kindly mark It has correct.
Thankyou.
Happy to help 🙂
Views
Replies
Total Likes