Verifying jQuery and jQuery UI CVE coverage in Adobe Experience Manager 6.5

This article explains how to determine whether specific jQuery and jQuery UI vulnerabilities (CVEs) flagged by security scans are already addressed in your Adobe Experience Manager (AEM) 6.5 environment, and provides guidance on next steps if new vulnerabilities are detected.

Description description

Security scans report vulnerabilities related to jQuery and jQuery UI libraries bundled with AEM 6.5, based on detected version strings. However, AEM uses an Adobe-patched fork of jQuery and includes backported security fixes in supported service pack levels. Understanding which CVEs are addressed in your current AEM version and service pack is important for accurate vulnerability management.

Environment

  • Adobe Experience Manager (AEM) 6.5 (all supported deployment types)

Symptoms

  • Security scans report CVEs such as CVE-2021-41182, CVE-2021-41183, CVE-2021-41184, CVE-2022-31160, or CVE-2025-13465 based on detected jQuery or jQuery UI versions in AEM.
  • No active exploit or functional error is observed, but scan results raise concerns about unpatched vulnerabilities.

Cause

  • Security scanners often rely on library version strings and don’t detect backported security fixes present in AEM’s patched libraries. This can result in false positives.

Resolution resolution

Follow the steps below to resolve the issue:

  1. Verify your AEM version and service pack:

    • Log in to the AEM Web Console (For example: http://:/system/console/productinfo) or check the installed package list in the AEM Package Manager.

    • Note the AEM version and service pack (For example: 6.5.24.0).

  2. Review CVE coverage by service pack:

    • CVE-2021-41182, CVE-2021-41183, CVE-2021-41184: Fixed in AEM 6.5 Service Pack 16 (6.5.16.0) and later.

    • CVE-2022-31160: Fixed in AEM 6.5 Service Pack 19 (6.5.19.0) and later.

    • If your AEM environment is on 6.5.19.0 or later, these vulnerabilities are already addressed.

  3. Understand jQuery core patching in AEM:

    • AEM ships with a custom Adobe-patched fork of jQuery (version 1.12.4-aem) that includes backported fixes for major jQuery CVEs, even if the version string appears unchanged.
  4. Assess scanner findings for CVE-2025-13465:

    • This CVE isn’t currently listed as affecting the jQuery/jQuery UI versions shipped with AEM and doesn’t appear in any official AEM security bulletin.

    • Findings for this CVE are likely false positives based on version string detection.

  5. If your scanner flags a CVE not listed in AEM security bulletins or you have a proof-of-concept exploit that demonstrates a real vulnerability in your environment:

    • Collect details of the finding or exploit.

    • Submit a support request to Adobe for further investigation.

  6. Verification:

    • After confirming your AEM version and service pack, cross-check with the above fix levels to ensure all flagged CVEs are addressed.
recommendation-more-help
experience-cloud-kcs-help-kbarticles