CVE-2016-0956
Exposure of Sensitive Information to an Unauthorized Actor in Apache Sling Servlets Post
7.5
HIGH
CVSS 3.1
EPSS 13.3%
Description
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.
How to fix CVE-2016-0956
To remediate CVE-2016-0956, upgrade the affected package to a fixed version below.
- Maven/org.apache.sling:org.apache.sling.servlets.post—upgrade to 2.3.8 or later
Is CVE-2016-0956 being exploited?
Moderate — EPSS is 13.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.3.8
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |