Unauthenticated RCE via Broken Authorization in Adobe Experience Manager Forms JEE
AI analysis
Adobe Experience Manager Forms JEE contains an incorrect authorization flaw (CWE-863) that allows arbitrary code execution in the context of the current user. The vulnerability is network-reachable, requires no privileges, no user interaction, and has low attack complexity, earning it a maximum CVSS 3.1 score of 10.0 with a changed scope, meaning exploitation can impact resources beyond the vulnerable component's normal security boundary. An attacker who reaches an exposed AEM Forms JEE server could execute arbitrary code, compromising confidentiality, integrity, and availability of the affected system. Organizations running AEM Forms on JEE — an enterprise forms and document-services platform that is often deployed internet-facing to accept form submissions — are the affected population. There is no known public proof of concept and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation appears theoretical at this time.
What to do: Apply Adobe's security update for Experience Manager Forms JEE as soon as the patched version in Adobe's bulletin is available, prioritizing any instance reachable from the internet. Until patched, restrict external access to AEM Forms JEE endpoints via reverse proxy or network allowlisting and disable any unused servlets or services. Review server logs for unauthenticated requests to Forms JEE endpoints and indicators of unexpected process or code execution.
Affected
| Adobe Experience Manager Forms (JEE deployment) | — |
Estimated exposure
moderateLikely hundreds to low thousands of internet-exposed AEM Forms JEE installations, with a larger population of internal enterprise deployments — AEM Forms JEE is a licensed enterprise product with no public install counts; public internet scans typically show on the order of ten thousand exposed AEM endpoints overall, of which the Forms-on-JEE subset is a small fraction, so this is…
Description
Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.