Medium severity6.1NVD Advisory· Published Dec 9, 2017· Updated Jun 17, 2026
CVE-2017-11296
CVE-2017-11296
Description
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. A cross-site scripting vulnerability in Apache Sling Servlets Post 2.3.20 has been resolved in Adobe Experience Manager.
Affected products
6cpe:2.3:a:adobe:experience_manager:6.0.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:adobe:experience_manager:6.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:experience_manager:6.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:experience_manager:6.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:experience_manager:6.3.0:*:*:*:*:*:*:*
- (no CPE)range: 6.3, 6.2, 6.1, 6.0
- Range: 2.3.20
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/101844nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1039800nvdThird Party AdvisoryVDB Entry
- helpx.adobe.com/security/products/experience-manager/apsb17-41.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.