« Volver al listado

CVE-2021-21009

Estado: AnalizadaAlta (8.6)—

Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitation could allow an attacker to use the Campaign instance to issue unauthorized requests to internal or external resources.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-21009",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2021-21009",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-23T13:06:29.605174Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@adobe.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.6,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "Adobe",
          "product": "Campaign",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "20.3.1 and earlier"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "Gold Standard 10 and earlier"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "20.2.3 and earlier"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "20.1.3 and earlier"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "19.2.3 and earlier"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "19.1.7 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-01-13T23:15:14.133",
  "references": [
    {
      "url": "https://helpx.adobe.com/security/products/campaign/apsb21-04.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://helpx.adobe.com/security/products/campaign/apsb21-04.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@adobe.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitation could allow an attacker to use the Campaign instance to issue unauthorized requests to internal or external resources."
    },
    {
      "lang": "es",
      "value": "Adobe Campaign Classic Gold Standard versiones 10 (y anteriores), versiones 20.3.1 (y anteriores), versiones 20.2.3 (y anteriores), versiones 20.1.3 (y anteriores), versiones 19.2.3 (y anteriores) y versiones 19.1.7 (y anteriores), están afectados por una vulnerabilidad de tipo server-side request forgery (SSRF). Una explotación con éxito podría permitir a un atacante usar la instancia de Campaign para emitir peticiones no autorizadas hacia recursos internos o externos"
    }
  ],
  "lastModified": "2026-08-24T18:07:51.887",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:campaign:*:*:*:*:standard:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D9C5CBB-3A6C-4627-B356-25EC2969034D",
              "versionEndExcluding": "19.1.8"
            },
            {
              "criteria": "cpe:2.3:a:adobe:campaign:*:*:*:*:standard:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39508BB1-A036-46A8-BDC9-E687C91C6B9B",
              "versionEndExcluding": "19.2.4",
              "versionStartIncluding": "19.2"
            },
            {
              "criteria": "cpe:2.3:a:adobe:campaign:*:*:*:*:standard:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9CA5F707-08A3-49A0-81C4-31132A513853",
              "versionEndExcluding": "20.1.4",
              "versionStartIncluding": "20.1"
            },
            {
              "criteria": "cpe:2.3:a:adobe:campaign:*:*:*:*:standard:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E3F3DB0-628E-4D91-9D3D-C50D88FCBC24",
              "versionEndExcluding": "20.2.4",
              "versionStartIncluding": "20.2"
            },
            {
              "criteria": "cpe:2.3:a:adobe:campaign:*:*:*:*:standard:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ACF4FEC1-4E3C-4287-AB62-1187108FC697",
              "versionEndExcluding": "20.3.3",
              "versionStartIncluding": "20.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@adobe.com"
}