AEM Forms 6.5 LTS SP2: Wildcard vulnerability in /libs/xfaforms/render/json.jsp resolved
This article explains how the wildcard-related vulnerability associated with /libs/xfaforms/render/json.jsp has been addressed in Adobe Experience Manager (AEM) Forms 6.5 LTS SP2 and how to verify its resolution.
Description description
Environment
- Adobe Experience Manager (AEM) 6.5
- Adobe Experience Manager (AEM) - Forms
Issue/Symptoms
A security vulnerability related to the file /libs/xfaforms/render/json.jsp was present in earlier versions of Adobe Experience Manager (AEM) Forms. In AEM Forms 6.5 service packs, including LTS SP2, this file was removed as part of a security fix. The absence of this file in your AEM instance confirms that the vulnerability has been resolved.
Resolution resolution
To verify that the wildcard-related vulnerability has been resolved, follow these steps:
- Confirm that your AEM Forms instance is running version 6.5 LTS SP2 or later.
- Log in to your AEM instance as an administrator.
- Open the CRXDE Lite interface by navigating to
https://<your-server>:<port>/crx/dein your web browser. - In the CRXDE Lite interface, use the search function to look for the path
/libs/xfaforms/render/json.jsp. - If the file
/libs/xfaforms/render/json.jspis not present, the vulnerability has been addressed in your environment. - If the file is present, contact Adobe Support.
recommendation-more-help
experience-cloud-kcs-help-kbarticles