A zero-day vulnerability has been identified in the popular content management solution, Adobe Experience Manager (AEM), used by large and well-known companies, such as Deloitte, Dell , and Microsoft.
See also: Microsoft/Adobe exploits: Hackers' favorite choices

The vulnerability was discovered by two members of the Detectify ethical hacking community . If left unpatched, the vulnerability could allow attackers to bypass authentication and gain access to the CRX Package Manager, leaving applications vulnerable to remote code execution (RCE) attacks.
“With access to the CRX Package Manager, an attacker could upload a malicious package to Adobe Experience Manager to exploit it in an RCE attack and gain full control of the application,” a Detectify spokesperson said.
Researchers Ai Ho (@j3ssiejjj) and Bao Bui (@Jok3rDb) uncovered the zero-day vulnerability and named it AEM CRX Bypass. According to their research, several large organizations were affected by the bug, including Mastercard, LinkedIn, PlayStation, and McAfee.
See also: Apple: Fixed two iOS zero-day vulnerabilities that allowed hacking of older iPhones
The vulnerability occurs in CR package endpoints and can be mitigated by blocking public access to CRX consoles.
A Detectify spokesperson explained: “Access to the CRX Package Manager is achieved by bypassing authentication in Dispatcher, the caching and/or load balancing tool of Adobe Experience Manager.”

“The Dispatcher checks the user's access rights for a page before delivering the cached page and is an essential part of most – if not all – AEM installations. It can be bypassed by adding many special characters to the request“.
See also: Adobe patches critical vulnerabilities in Photoshop and Digital Editions
Security researcher Bao Bui started participating in bug bounty programs and “hunting” bugs a year ago. Security engineer and developer Ai Ho has been active in the bug bounty scene for two years, building his own debugging tools, which he shares on GitHub.
The zero-day vulnerability in Adobe Experience Manager was reported to the company, which quickly released a patch to fix it.
Source: Infosecurity Magazine
