CVE-2017-2989 is a critical input validation bypass vulnerability affecting Adobe Campaign versions Build 8770 and earlier. This flaw allows an unauthenticated attacker to remotely read, write, or delete data from the Campaign database with low attack complexity. While the CVSS score is 9.1 (CRITICAL), there is no public exploit code available, nor is it listed on CISA's KEV catalog, suggesting it is not actively exploited in the wild. Despite its age, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.11CPE matchmatch criteria | cpe:2.3:a:adobe:campaign:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.