AEM Forms 6.5 LTS SP2: Wildcard vulnerability in /libs/xfaforms/render/json.jsp resolved

This article explains how the wildcard-related vulnerability associated with /libs/xfaforms/render/json.jsp has been addressed in Adobe Experience Manager (AEM) Forms 6.5 LTS SP2 and how to verify its resolution.

Description description

Environment

  • Adobe Experience Manager (AEM) 6.5
  • Adobe Experience Manager (AEM) - Forms

Issue/Symptoms

A security vulnerability related to the file /libs/xfaforms/render/json.jsp was present in earlier versions of Adobe Experience Manager (AEM) Forms. In AEM Forms 6.5 service packs, including LTS SP2, this file was removed as part of a security fix. The absence of this file in your AEM instance confirms that the vulnerability has been resolved.

Resolution resolution

To verify that the wildcard-related vulnerability has been resolved, follow these steps:

  1. Confirm that your AEM Forms instance is running version 6.5 LTS SP2 or later.
  2. Log in to your AEM instance as an administrator.
  3. Open the CRXDE Lite interface by navigating to https://<your-server>:<port>/crx/de in your web browser.
  4. In the CRXDE Lite interface, use the search function to look for the path /libs/xfaforms/render/json.jsp.
  5. If the file /libs/xfaforms/render/json.jsp is not present, the vulnerability has been addressed in your environment.
  6. If the file is present, contact Adobe Support.
recommendation-more-help
experience-cloud-kcs-help-kbarticles