Improper Input Validation in Adobe Experience Manager Affects User Security
CVE-2025-47096

3.5LOW

Key Information:

Vendor

Adobe

Vendor
CVE Published:
10 June 2025

What is CVE-2025-47096?

Adobe Experience Manager versions 6.5.22 and earlier are susceptible to an improper input validation vulnerability, which could allow an attacker to execute arbitrary code within the context of the current user. This vulnerability necessitates user interaction, as the victim must open a specially crafted malicious file for exploitation to occur. While low privileges are required for the attacker to exploit the flaw, the potential risk to user security is significant.

Affected Version(s)

Adobe Experience Manager 0 <= 6.5.22

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.