CVE-2019-16469 describes an expression language injection vulnerability affecting multiple versions of Adobe Experience Manager (AEM). This flaw, with a CVSS score of 7.5 (HIGH), can be exploited remotely without user interaction, potentially leading to sensitive information disclosure. While not currently listed in CISA's KEV catalog, public exploit templates exist, and the vulnerability has garnered significant community discussion and media coverage, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.5.0, < 6.5.3.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.