Show plain JSON{"containers": {"cna": {"affected": [{"product": "Experience Manager", "vendor": "Adobe", "versions": [{"lessThanOrEqual": "6.3.3.8", "status": "affected", "version": "unspecified", "versionType": "custom"}, {"lessThanOrEqual": "6.4.8.3", "status": "affected", "version": "unspecified", "versionType": "custom"}, {"lessThanOrEqual": "6.5.7.0", "status": "affected", "version": "unspecified", "versionType": "custom"}, {"lessThanOrEqual": "AEM Cloud Service", "status": "affected", "version": "unspecified", "versionType": "custom"}]}], "datePublic": "2021-03-09T00:00:00", "descriptions": [{"lang": "en", "value": "AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by an Improper Access Control vulnerability. An unauthenticated attacker could leverage this vulnerability to cause an application denial-of-service in the context of the current user."}], "metrics": [{"cvssV3_1": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1"}}], "problemTypes": [{"descriptions": [{"cweId": "CWE-284", "description": "Improper Access Control (CWE-284)", "lang": "en", "type": "CWE"}]}], "providerMetadata": {"dateUpdated": "2021-06-28T13:41:54", "orgId": "078d4453-3bcd-4900-85e6-15281da43538", "shortName": "adobe"}, "references": [{"tags": ["x_refsource_MISC"], "url": "https://helpx.adobe.com/security/products/experience-manager/apsb21-15.html"}], "source": {"discovery": "EXTERNAL"}, "title": "Adobe Experience Manager broken access control in DSRPReindexServlet could lead to denial-of-service", "x_legacyV4Record": {"CVE_data_meta": {"ASSIGNER": "psirt@adobe.com", "DATE_PUBLIC": "2021-03-09T23:00:00.000Z", "ID": "CVE-2021-21083", "STATE": "PUBLIC", "TITLE": "Adobe Experience Manager broken access control in DSRPReindexServlet could lead to denial-of-service"}, "affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"product_name": "Experience Manager", "version": {"version_data": [{"version_affected": "<=", "version_value": "6.3.3.8"}, {"version_affected": "<=", "version_value": "6.4.8.3"}, {"version_affected": "<=", "version_value": "6.5.7.0"}, {"version_affected": "<=", "version_value": "AEM Cloud Service"}]}}]}, "vendor_name": "Adobe"}]}}, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": {"description_data": [{"lang": "eng", "value": "AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by an Improper Access Control vulnerability. An unauthenticated attacker could leverage this vulnerability to cause an application denial-of-service in the context of the current user."}]}, "impact": {"cvss": {"attackComplexity": "Low", "attackVector": "Network", "availabilityImpact": "High", "baseScore": 7.5, "baseSeverity": "Medium", "confidentialityImpact": "None", "integrityImpact": "None", "privilegesRequired": "None", "scope": "Unchanged", "userInteraction": "None", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1"}}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "Improper Access Control (CWE-284)"}]}]}, "references": {"reference_data": [{"name": "https://helpx.adobe.com/security/products/experience-manager/apsb21-15.html", "refsource": "MISC", "url": "https://helpx.adobe.com/security/products/experience-manager/apsb21-15.html"}]}, "source": {"discovery": "EXTERNAL"}}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-03T18:01:14.127Z"}, "title": "CVE Program Container", "references": [{"tags": ["x_refsource_MISC", "x_transferred"], "url": "https://helpx.adobe.com/security/products/experience-manager/apsb21-15.html"}]}]}, "cveMetadata": {"assignerOrgId": "078d4453-3bcd-4900-85e6-15281da43538", "assignerShortName": "adobe", "cveId": "CVE-2021-21083", "datePublished": "2021-06-28T13:41:54.807477Z", "dateReserved": "2020-12-18T00:00:00", "dateUpdated": "2024-09-16T16:23:53.755Z", "state": "PUBLISHED"}, "dataType": "CVE_RECORD", "dataVersion": "5.1"}