HomeSecurityAdobe: Fixes critical vulnerabilities in InDesign and Framemaker

Adobe: Fixes Critical Vulnerabilities in InDesign and Framemaker

Adobe InDesign, Adobe Framemaker , and Adobe Experience Manager received updates to fix critical vulnerabilities.

Adobe: Fixes Critical Vulnerabilities in InDesign and Framemaker

Adobe has released security updates to fix critical vulnerabilities that could allow attackers to execute malicious code on devices running vulnerable versions of Adobe InDesign, Adobe Framemaker, and Adobe Experience Manager .

In total, Adobe patched 18 vulnerabilities. All of them are rated from serious to critical. Some of these vulnerabilities could lead to JavaScript code execution in the browser and the disclosure of sensitive information.

Adobe advises customers to update vulnerable applications to the latest versions as soon as possible to stay safe.

Adobe InDesign, Adobe Framemaker Adobe Experience Manager

Security Update APSB20-52 for Adobe InDesign

Adobe has released security for Adobe InDesign for macOS. The updates fix memory-related vulnerabilities that could lead to code execution.

macOS users should install the Adobe InDesign 15.1.2 update to fix the following five critical vulnerabilities.

Vulnerability CategoryVulnerability ImpactSeverityCVE Number
Memory Corruption Arbitrary Code ExecutionCriticalCVE-2020-9727 CVE-2020-9728 CVE-2020-9729 CVE-2020-9730 CVE-2020-9731    

Security Update APSB20-54 for Adobe Framemaker

Adobe has released security for Adobe Framemaker for Windowsto fix “stack-based buffer overflow issues,” which could also allow code execution.

Users should immediately install Adobe Framemaker version 2019.0.7 to fix these critical bugs.

Vulnerability CategoryVulnerability ImpactSeverityCVE Numbers
Out-of-Bounds Read Arbitrary code executionCriticalCVE-2020-9726 
Stack-based Buffer Overflow Arbitrary code executionCriticalCVE-2020-9725
vulnerabilities

Security Update APSB20-56 for Adobe Experience Manager

Finally, Adobe released updates for Adobe Experience Manager and the AEM Forms add-on, which fix “cross-site scripting” vulnerabilities. The bugs could lead to JavaScript code execution, HTML injection in the browser, and information disclosure.

Users must install Adobe Experience Manager version 6.5.6.0 or 6.4.8.2 and AEM Forms add-on Service Pack 6 to fix these security vulnerabilities.

Vulnerability CategoryVulnerability ImpactSeverityCVE NumberAffected Versions
Cross-site scripting (stored)Arbitrary JavaScript execution in the browserCriticalCVE-2020-9732AEM Forms SP5 and earlier
Execution with Unnecessary PrivilegesSensitive Information DisclosureImportantCVE-2020-9733AEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlier
Cross-site scripting (stored)Arbitrary JavaScript execution in the browserCriticalCVE-2020-9734AEM Forms SP5 and earlier
Cross-site scripting (stored)Arbitrary JavaScript execution in the browserImportantCVE-2020-9735AAEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlierAEM 6.3.3.8 and earlierAEM 6.2 SP1-CFP20 and earlier
Cross-site scripting (stored)Arbitrary JavaScript execution in the browserImportantCVE-2020-9736AEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlierAEM 6.3.3.8 and earlierAEM 6.2 SP1-CFP20 and earlier
Cross-site scripting (stored)Arbitrary JavaScript execution in the browserImportantCVE-2020-9737AEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlierAEM 6.3.3.8 and earlierAEM 6.2 SP1-CFP20 and earlier
Cross-site scripting (stored)Arbitrary JavaScript execution in the browserImportantCVE-2020-9738AEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlierAEM 6.3.3.8 and earlierAEM 6.2 SP1-CFP20 and earlier
Cross-site scripting (stored)Arbitrary JavaScript execution in the browserCriticalCVE-2020-9740AEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlierAEM 6.3.3.8 and earlierAEM 6.2 SP1-CFP20 and earlier
Cross-site scripting (stored)Arbitrary JavaScript execution in the browserCriticalCVE-2020-9741AEM Forms SP5 and earlier
Cross-site scripting (reflected)Arbitrary JavaScript execution in the browserCriticalCVE-2020-9742AEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlierAEM 6.3.3.8 and earlier
HTML injectionArbitrary HTML injection in the browserImportantCVE-2020-9743AEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlierAEM 6.3.3.8 and earlierAEM 6.2 SP1-CFP20 and earlier
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS