CVE-2016-0956
high · 7.5The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.
7.5
CVSS
51.2%
EPSS (exploit prob.)
99th
EPSS percentile
2016-02-10
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | sling | all versions |
| adobe | experience_manager | 5.6.1 |
| adobe | experience_manager | 6.0.0 |
| adobe | experience_manager | 6.1.0 |
| apple | mac_os_x | all versions |
| linux | linux_kernel | all versions |
| microsoft | windows | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/135720/Apache-Sling-Framework-2.3.6-Information-Disclosure.html
- http://seclists.org/fulldisclosure/2016/Feb/48
- http://www.securityfocus.com/archive/1/537498/100/0/threaded
- https://helpx.adobe.com/security/products/experience-manager/apsb16-05.html
- https://www.exploit-db.com/exploits/39435/
- http://packetstormsecurity.com/files/135720/Apache-Sling-Framework-2.3.6-Information-Disclosure.html
- http://seclists.org/fulldisclosure/2016/Feb/48
- http://www.securityfocus.com/archive/1/537498/100/0/threaded
- https://helpx.adobe.com/security/products/experience-manager/apsb16-05.html
- https://www.exploit-db.com/exploits/39435/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-0956