CVE-2016-0957 describes a critical vulnerability in Adobe Experience Manager (AEM) Dispatcher versions prior to 4.1.5, affecting AEM 5.6.1, 6.0.0, and 6.1.0, as well as products from Apple, Linux, and Microsoft. This flaw allows remote attackers to bypass URL filtering rules due to improper implementation. With a CVSS score of 7.5 (High), the vulnerability is easily exploitable over the network without authentication or user interaction, potentially leading to high confidentiality impacts. While not listed in CISA's KEV catalog, its high EPSS score (0.9246) and FAUCET Risk Score (99/100) indicate a significant likelihood of exploitation, with Nuclei templates available for detection, and it has garnered community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.1.4CPE matchmatch criteria | cpe:2.3:a:adobe:dispatcher:*:*:*:*:*:*:*:* | ||
5.6.1CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:5.6.1:*:*:*:*:*:*:* | ||
6.0.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:6.0.0:*:*:*:*:*:*:* | ||
6.1.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:6.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.