CVE-2023-48441
Status: ModifiedMedium (5.3)—
Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Access Control vulnerability. An attacker could leverage this vulnerability to achieve a low-confidentiality impact within the application. Exploitation of this issue does not require user interaction.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Base score: 5.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.78%
- Percentile among all scored CVEs: 55
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-284
References
Raw JSON (NVD)
Show
{
"id": "CVE-2023-48441",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@adobe.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@adobe.com",
"affectedData": [
{
"vendor": "Adobe",
"product": "Adobe Experience Manager",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "6.5.18"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2023-12-15T11:15:10.463",
"references": [
{
"url": "https://helpx.adobe.com/security/products/experience-manager/apsb23-72.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "psirt@adobe.com"
},
{
"url": "https://helpx.adobe.com/security/products/experience-manager/apsb23-72.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@adobe.com",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Access Control vulnerability. An attacker could leverage this vulnerability to achieve a low-confidentiality impact within the application. Exploitation of this issue does not require user interaction."
},
{
"lang": "es",
"value": "Adobe Experience Manager en la versión 6.5.18 y anteriores se ven afectadas por una vulnerabilidad de control de acceso inadecuado. Un atacante podría aprovechar esta vulnerabilidad para lograr un impacto de baja confidencialidad dentro de la aplicación. La explotación de este problema no requiere la interacción del usuario."
}
],
"lastModified": "2026-06-17T06:34:15.450",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA275504-C2EE-42D5-AC1B-01DC1DAC1CA1",
"versionEndIncluding": "6.5.18.0"
},
{
"criteria": "cpe:2.3:a:adobe:experience_manager:-:*:*:*:aem_cloud_service:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A88C919F-4221-4669-A725-06094F811012"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@adobe.com"
}