Security vulnerabilities affect 6.5 LTS SP1 in Adobe Experience Manager
Adobe Security Bulletin APSB26-74 identifies security vulnerabilities affecting Adobe Experience Manager 6.5 LTS Service Pack 1. To fix this, review the bulletin, apply the non-affected AEM release specified in its Solution section, and install any required hotfix.
Description description
Environment
Adobe Experience Manager 6.5 LTS Service Pack 1 on all supported platforms
Issue/Symptoms
Adobe Security Bulletin APSB26-74 documents security vulnerabilities affecting Adobe Experience Manager 6.5 LTS Service Pack 1. The issue is based on the published security advisory and doesn’t produce a specific error message or stack trace.
- The environment runs Adobe Experience Manager 6.5 LTS Service Pack 1.
- The installed version is listed as affected in
APSB26-74. - No specific error message or stack trace identifies this issue.
- The environment requires the security update described in the bulletin.
Cause
The AEM environment runs a version listed as affected in Adobe Security Bulletin APSB26-74. The bulletin identifies the applicable non-affected release and any required hotfix.
Resolution resolution
To remediate the vulnerabilities, follow these steps:
-
Review Adobe Security Bulletin APSB26-74 to understand the vulnerabilities, affected versions, affected components, and remediation requirements.
-
Compare the installed AEM version with the affected and fixed versions listed in the bulletin.
- Because the bulletin lists AEM 6.5 LTS Service Pack 2 and earlier as affected, don’t stop at Service Pack 2 when applying this remediation.
- Use the non-affected AEM release specified in the bulletin’s Solution section.
-
Download and install the non-affected AEM release from Adobe Software Distribution.
- Follow the installation instructions in the release documentation for the applicable AEM version.
-
After applying the non-affected release, install any additional security hotfix specified in
APSB26-74.- If the hotfix is available through Adobe Software Distribution, download it and follow the associated installation instructions.
- If the hotfix isn’t available for direct download, follow the instructions in the security bulletin to obtain it.
-
Deploy the release and the required hotfix across all applicable environments.
-
Rerun your security scans after deployment and confirm that the results align with the remediation guidance in
APSB26-74.