← Vulnerability feed

Vulnerability record · CVE-2016-0957 · published 10 February 2016

CVE-2016-0957: Adobe Experience Manager Dispatcher URL filter bypass

Adobe · Dispatcher

Adobe Experience Manager Dispatcher before 4.1.5 fails to properly implement a URL filter, allowing remote attackers to bypass dispatcher rules via unspecified vectors. Because the dispatcher is the front-end gatekeeper for AEM, a bypass can expose protected paths and content that the rules were meant to block. The record does not specify which rules or paths are affected.

7.5 CVSS 3.0 High EPSS 52% · top 1.1%
7.5CVSS 3.0 base score, v2 7.8
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable filter bypass with high confidentiality impact and very high EPSS, though no confirmed in-the-wild exploitation is recorded.

What it is

Adobe Experience Manager Dispatcher before 4.1.5 fails to properly implement a URL filter, allowing remote attackers to bypass dispatcher rules via unspecified vectors. Because the dispatcher is the front-end gatekeeper for AEM, a bypass can expose protected paths and content that the rules were meant to block. The record does not specify which rules or paths are affected.

Impact

An unauthenticated remote attacker can reach resources that dispatcher rules were intended to deny, gaining access to information that should have been filtered. The CVSS vector indicates high confidentiality impact with no integrity or availability effect.

Attack surface

Reachable over the network through HTTP requests to the dispatcher; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The exact request pattern is not described in the record.

Exploitation

Not listed in CISA KEV and no public exploit reference is provided, but EPSS is high at roughly 0.52 (99th percentile), indicating elevated likelihood of attempted exploitation. The only references are Adobe's vendor advisory and patch page.

What to do

  • Upgrade Dispatcher to version 4.1.5 or later as directed in Adobe advisory APSB16-05.
  • Review and tighten dispatcher filter rules, denying by default and allowing only required paths.
  • Restrict direct network access to AEM publish/author instances so traffic must pass through the patched dispatcher.
  • Monitor for requests that attempt path traversal, encoding tricks, or unusual URL patterns against the dispatcher.
  • Confirm the deployed Dispatcher version and re-verify filter configuration after patching.

Detection

  • Inspect dispatcher and web server access logs for requests to paths that should be blocked by filter rules.
  • Alert on URL-encoded, double-encoded, or traversal-style sequences in request paths.
  • Baseline normal request paths and flag deviations that reach protected AEM endpoints.
  • Correlate repeated filter-bypass attempts from the same source IP across a short window.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0957 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-19232Adobe experience manager incorrect authorization vulnerabilityAdobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the …EPSS 0.59%9.8CVE-2025-49533Adobe Experience Manager untrusted deserialization enables remote code executionAdobe Experience Manager (MS) versions 6.5.23.0 and earlier contain a deserialization of untrusted data flaw (CWE-502) that can lead to arbitrary cod…EPSS 53%analysed9.8CVE-2024-26029Adobe experience manager improper access control vulnerabilityAdobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature…EPSS 0.89%9.8CVE-2021-40722Adobe experience manager xml external entity (xxe) vulnerabilityAEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that c…EPSS 3.3%9.8CVE-2019-8088Adobe experience manager command injection vulnerabilityAdobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code …EPSS 5.8%9.8CVE-2019-7964Adobe experience manager vulnerabilityAdobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successful exploitation could lead to remote code executi…EPSS 10%9.8CVE-2017-3108Adobe experience manager unrestricted file upload vulnerabilityAdobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability.EPSS 8.6%9.6CVE-2026-48359Adobe experience manager xml external entity (xxe) vulnerabilityAdobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2016-0957), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.