Vulnerability record · CVE-2016-0957 · published 10 February 2016
CVE-2016-0957: Adobe Experience Manager Dispatcher URL filter bypass
Adobe · Dispatcher
Adobe Experience Manager Dispatcher before 4.1.5 fails to properly implement a URL filter, allowing remote attackers to bypass dispatcher rules via unspecified vectors. Because the dispatcher is the front-end gatekeeper for AEM, a bypass can expose protected paths and content that the rules were meant to block. The record does not specify which rules or paths are affected.
Description
Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable filter bypass with high confidentiality impact and very high EPSS, though no confirmed in-the-wild exploitation is recorded.
What it is
Adobe Experience Manager Dispatcher before 4.1.5 fails to properly implement a URL filter, allowing remote attackers to bypass dispatcher rules via unspecified vectors. Because the dispatcher is the front-end gatekeeper for AEM, a bypass can expose protected paths and content that the rules were meant to block. The record does not specify which rules or paths are affected.
Impact
An unauthenticated remote attacker can reach resources that dispatcher rules were intended to deny, gaining access to information that should have been filtered. The CVSS vector indicates high confidentiality impact with no integrity or availability effect.
Attack surface
Reachable over the network through HTTP requests to the dispatcher; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The exact request pattern is not described in the record.
Exploitation
Not listed in CISA KEV and no public exploit reference is provided, but EPSS is high at roughly 0.52 (99th percentile), indicating elevated likelihood of attempted exploitation. The only references are Adobe's vendor advisory and patch page.
What to do
- Upgrade Dispatcher to version 4.1.5 or later as directed in Adobe advisory APSB16-05.
- Review and tighten dispatcher filter rules, denying by default and allowing only required paths.
- Restrict direct network access to AEM publish/author instances so traffic must pass through the patched dispatcher.
- Monitor for requests that attempt path traversal, encoding tricks, or unusual URL patterns against the dispatcher.
- Confirm the deployed Dispatcher version and re-verify filter configuration after patching.
Detection
- Inspect dispatcher and web server access logs for requests to paths that should be blocked by filter rules.
- Alert on URL-encoded, double-encoded, or traversal-style sequences in request paths.
- Baseline normal request paths and flag deviations that reach protected AEM endpoints.
- Correlate repeated filter-bypass attempts from the same source IP across a short window.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/experience-manager/apsb16-05.html | PatchVendor Advisory |
| https://helpx.adobe.com/security/products/experience-manager/apsb16-05.html | PatchVendor Advisory |
Track CVE-2016-0957 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0957), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.