Security vulnerabilities affect 6.5 LTS SP1 in Adobe Experience Manager

Adobe Security Bulletin APSB26-74 identifies security vulnerabilities affecting Adobe Experience Manager 6.5 LTS Service Pack 1. To fix this, review the bulletin, apply the non-affected AEM release specified in its Solution section, and install any required hotfix.

Description description

Environment

Adobe Experience Manager 6.5 LTS Service Pack 1 on all supported platforms

Issue/Symptoms

Adobe Security Bulletin APSB26-74 documents security vulnerabilities affecting Adobe Experience Manager 6.5 LTS Service Pack 1. The issue is based on the published security advisory and doesn’t produce a specific error message or stack trace.

  • The environment runs Adobe Experience Manager 6.5 LTS Service Pack 1.
  • The installed version is listed as affected in APSB26-74.
  • No specific error message or stack trace identifies this issue.
  • The environment requires the security update described in the bulletin.

Cause

The AEM environment runs a version listed as affected in Adobe Security Bulletin APSB26-74. The bulletin identifies the applicable non-affected release and any required hotfix.

Resolution resolution

To remediate the vulnerabilities, follow these steps:

  1. Review Adobe Security Bulletin APSB26-74 to understand the vulnerabilities, affected versions, affected components, and remediation requirements.

  2. Compare the installed AEM version with the affected and fixed versions listed in the bulletin.

    • Because the bulletin lists AEM 6.5 LTS Service Pack 2 and earlier as affected, don’t stop at Service Pack 2 when applying this remediation.
    • Use the non-affected AEM release specified in the bulletin’s Solution section.
  3. Download and install the non-affected AEM release from Adobe Software Distribution.

    • Follow the installation instructions in the release documentation for the applicable AEM version.
  4. After applying the non-affected release, install any additional security hotfix specified in APSB26-74.

    • If the hotfix is available through Adobe Software Distribution, download it and follow the associated installation instructions.
    • If the hotfix isn’t available for direct download, follow the instructions in the security bulletin to obtain it.
  5. Deploy the release and the required hotfix across all applicable environments.

  6. Rerun your security scans after deployment and confirm that the results align with the remediation guidance in APSB26-74.

recommendation-more-help
experience-cloud-kcs-help-kbarticles