Describing the flaws, Adobe stated in its advisory,
“These updates resolve one reflected cross-site scripting vulnerability rated Moderate, and one stored cross-site scripting vulnerability rated Important that could result in sensitive information disclosure.”Both the Stored Cross-site Scripting vulnerability (CVE-2018-19726) and the Reflected Cross-site Scripting (CVE-2018-19727) affected AEM versions 6.3 and 6.4. Whereas, the vulnerability CVE-2018-19726 also affected the earlier versions: AEM 6.0, 6.1, and 6.2.
Adobe has rolled-out patches in the latest versions of Adobe Experience Manager and has recommended the users to update their devices.
The recent AEM fixes mark the third consecutive patch in three weeks. Interestingly, in all three instances, Adobe did not release any patches for fixing security flaws in Adobe Flash. Does this mean the software is being properly tested before release? Or, shall we expect to receive updates in the next week again? Not to forget that Adobe has already announced ending support for Flash soon.
Take your time to comment on this article.