Slide 72
Slide 72 text
SSRF in ReportingServicesProxyServlet
CVE-2018-12809
• Versions: 6.0, 6.1, 6.2, 6.3, 6.4
• Allows to see the response
• Leak secrets (IAM creds), RXSS (bypasses XSS filters), bypass dispatcher
• https://helpx.adobe.com/security/products/experience-manager/apsb18-23.html
/libs/cq/contentinsight/content/proxy.reportingservices.json
/libs/cq/contentinsight/proxy/reportingservices.json.GET.servlet
72/110