Adobe Experience Manager Forms
cpe:2.3:a:adobe:experience_manager_forms:*:*:*:*:*:*:*
- <= 6.5.23.0
A deserialization vulnerability allowing arbitrary code execution has been identified in Adobe Experience Manager (AEM) Forms on JEE, specifically in versions 6.5.23.0 and earlier. This vulnerability arises from the deserialization of untrusted data, and exploitation does not require user interaction.
Exploitation of this vulnerability could result in arbitrary code execution on the server where AEM Forms is running.
Users are advised to update to Adobe Experience Manager (AEM) Forms on JEE version 6.5.0.0.20250527.0. Update instructions are available on the Adobe Experience League website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.