Among these, the important security flaws include a cross-site request forgery (CVE-2019-7953) and stored cross-site scripting (CVE-2019-7954).
Besides, the moderate severity flaw included a reflected cross-site scripting vulnerability (CVE-2019-7955). The vendors acknowledged Lorenzo Pirondini for reporting this flaw.
The Adobe Experience Manager versions affected by these vulnerabilities include 6.0, 6.1, 6.2, 6.3, and 6.4. Adobe has fixed all these vulnerabilities in the respective AEM versions 6.3, 6.4, and 6.5.
Regarding Adobe Bridge CC, an important out-of-bounds read vulnerability (CVE-2019-7963) existed that could result in information disclosure. As stated in Adobe’s advisory,
A vulnerability… occurs when parsing malformed SVG images. This can result in an out-of-bounds memory read which leads to information (memory address) disclosure in the context of current user.The vulnerability specifically affected the Adobe Bridge CC versions 9.0.2 and earlier. Whereas, the vendors fixed the flaw with version 9.1. They also credited Trend Micro’s Zero Day Initiative researcher, Francis Provencher, for reporting the flaw.
As for the vulnerability in Adobe Dreamweaver, an important Insecure Library Loading (DLL hijacking) flaw affected the Adobe Dreamweaver direct download installer versions including and prior to 19.0 and 18.0. This important vulnerability (CVE-2019-7956) could lead to privilege escalation upon an exploit.
Adobe has fixed this flaw with the release of Adobe Dreamweaver direct download installer 2019 and 2018 releases. Besides, Adobe also thanked the researcher, Honc, in their advisory for reporting this issue.
Users of the respective Adobe products must ensure updating their systems to the patched software versions.
This month’s security updates do not address any critical security flaws, unlike the updates released in May and June 2019.
Take your time to comment on this article.