Adobe Experience Manager CRX Bypass: The 0-Day That Took Control Over Some Enterprise AEM CRX Package Manager

Adobe Experience Manager (AEM) is a widely used content management solution for building digital customer experiences, like websites, mobile apps and forms. Comprehensive and easy to use, AEM has become the preferred Content Management System (CMS) for many high-profile enterprises. This bug allows attackers to bypass authentication and gain access to CRX Package Manager. Packages enable the importing and exporting of repository content, and the Package Manager can be used for configuring, building, downloading, installing and deleting packages on local AEM installations.

Read more…