CVE-2021-21009
גבוהה 8.6
תיאור (מקור, אנגלית)
Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitation could allow an attacker to use the Campaign instance to issue unauthorized requests to internal or external resources.
מדדים
- CVSS 3.1
-
8.6 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N - EPSS — סבירות ניצול
- 3% (אחוזון 100) נכון ל-17/9/2026
- CWE
- CWE-918
מוצרים מושפעים
adobe: campaign; linux: linux kernel; microsoft: windows
קישורים
- https://helpx.adobe.com/security/products/campaign/apsb21-04.html Vendor Advisory
- https://helpx.adobe.com/security/products/campaign/apsb21-04.html Vendor Advisory