Adobe Security Bulletin
Security updates available for Adobe Experience Manager | APSB18-36
Bulletin ID Date Published Priority
APSB18-36 October 09, 2018 2

Summary

Adobe has released security updates for Adobe Experience Manager. These updates resolve two reflected cross-site scripting vulnerabilities rated Moderate, and three stored cross-site scripting vulnerabilities rated Important that could result in sensitive information disclosure.

Affected product versions

Product Version Platform
Adobe Experience Manager

6.4

6.3

6.2

6.1

6.0

All

Solution

Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:

Product

Version

Platform

Priority

Availability

 

 

 

Adobe Experience Manager

6.4

All

2

Releases and Updates

6.3

All

2

Releases and Updates

6.2

All

2

Releases and Updates

6.1

All

2

Releases and Updates

6.0

All

2

Releases and Updates

Please contact Adobe customer care for assistance with earlier AEM versions.

Vulnerability details

Vulnerability Category Vulnerability Impact Severity CVE Numbers Affected Version Download Package

 

 

Stored Cross-site Scripting

 

 

 

 

Sensitive Information disclosure

 

 

 

 

Important

 

 

 

 

CVE-2018-15969

 

 

 

 

AEM 6.3

 

 

AEM 6.4

 

 

 

 

Service Pack for 6.3 - AEM-6.3.3.0

 

 

Service Pack for 6.4 - AEM-6.4.2.0

 

 

 

 

 

 

 

Reflected Cross-site Scripting

 

 

 

 

Sensitive Information disclosure

 

 

 

 

Moderate

 

 

 

 

CVE-2018-15970

 

 

 

 

 

 

 

AEM 6.4

 

 

 

 

Service Pack for 6.4 - AEM-6.4.2.0

 

 

 

 

 

 

 

Reflected Cross-site Scripting

 

 

 

 

Sensitive Information disclosure

 

 

 

 

Moderate

 

 

 

 

CVE-2018-15971

 

 

 

 

 

 

 

AEM 6.4 

 

 

 

 

 

 

 

Service Pack for 6.4 - AEM-6.4.2.0

 

 

 

 

 

 

 

Stored Cross-site Scripting

 

 

 

 

Sensitive Information disclosure

 

 

 

 

Important

 

 

 

 

CVE-2018-15972

 

 

 

 

AEM 6.1 to AEM 6.4

 

 

 

 

Cumulative Fix Pack for 6.1 SP2 – AEM-6.1-SP2-CFP17

 

 

Cumulative Fix Pack for 6.2 SP1 – AEM-6.2-SP1-CFP15

 

 

Cumulative Fix Pack for 6.3 SP2 – AEM-6.3.2.2

 

 

Service Pack for 6.4 - AEM-6.4.2.0

 

 

 

 

 

 

 

Stored Cross-site Scripting

 

 

 

 

Sensitive Information disclosure

 

 

 

 

Important

 

 

 

 

CVE-2018-15973

 

 

 

 

AEM 6.0 to AEM 6.4

 

 

 

 

HOTFIX 25133 for AEM-6.0

 

 

Cumulative Fix Pack for 6.1 SP2 – AEM-6.1-SP2-CFP17

 

 

Cumulative Fix Pack for 6.2 SP1 – AEM-6.2-SP1-CFP16

 

 

Service Pack for 6.3 - AEM-6.3.3.0

 

 

Service Pack for 6.4 - AEM-6.4.2.0

 

 

Note:

The packages listed in the table above are the minimum fix packs to address the listed vulnerability.  For the latest versions, please see the release notes links referenced above.