{"document":{"aggregate_severity":{"text":"hoch"},"category":"csaf_base","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"de-DE","notes":[{"category":"legal_disclaimer","text":"Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen."},{"category":"description","text":"Apache Sling ist ein Open Source-Webframework für die Java-Plattform.","title":"Produktbeschreibung"},{"category":"summary","text":"Ein Angreifer kann mehrere Schwachstellen in Apache Sling ausnutzen, um einen Denial of Service Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.","title":"Angriff"},{"category":"general","text":"- Linux\n- Sonstiges\n- UNIX\n- Windows","title":"Betroffene Betriebssysteme"}],"publisher":{"category":"other","contact_details":"csaf-provider@cert-bund.de","name":"Bundesamt für Sicherheit in der Informationstechnik","namespace":"https://www.bsi.bund.de"},"references":[{"category":"self","summary":"WID-SEC-W-2026-3526 - CSAF Version","url":"https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3526.json"},{"category":"self","summary":"WID-SEC-2026-3526 - Portal Version","url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3526"},{"category":"external","summary":"CVE Record vom 2026-09-22","url":"https://www.cve.org/CVERecord?id=CVE-2026-91852"},{"category":"external","summary":"CVE Record vom 2026-09-22","url":"https://www.cve.org/CVERecord?id=CVE-2026-91928"},{"category":"external","summary":"CVE Record vom 2026-09-22","url":"https://www.cve.org/CVERecord?id=CVE-2026-94251"},{"category":"external","summary":"CVE Record vom 2026-09-22","url":"https://www.cve.org/CVERecord?id=CVE-2026-94243"},{"category":"external","summary":"CVE Record vom 2026-09-22","url":"https://www.cve.org/CVERecord?id=CVE-2026-91999"},{"category":"external","summary":"CVE Record vom 2026-09-22","url":"https://www.cve.org/CVERecord?id=CVE-2026-73192"},{"category":"external","summary":"CVE Record vom 2026-09-22","url":"https://www.cve.org/CVERecord?id=CVE-2026-92001"},{"category":"external","summary":"Apache Mailing List vom 2026-09-22","url":"https://lists.apache.org/thread/nd0ncdk5qb9gqvn0s10rmhnbk887k1qo"},{"category":"external","summary":"Apache Mailing List vom 2026-09-22","url":"https://lists.apache.org/thread/yfb1q6zob8mth5lr4jnsy3lhx9rfwb02"},{"category":"external","summary":"Apache Mailing List vom 2026-09-22","url":"https://lists.apache.org/thread/7zo0drh75qmk1xn7940hy4pxjs6h2b10"},{"category":"external","summary":"Apache Mailing List vom 2026-09-22","url":"https://lists.apache.org/thread/ohz47f6hrflsjvt9m24qz69qm5w4bwyr"},{"category":"external","summary":"Apache Mailing List vom 2026-09-22","url":"https://lists.apache.org/thread/xpcsdkr80ow9p13f7hp3ykrhzky9d4t4"},{"category":"external","summary":"Apache Mailing List vom 2026-09-22","url":"https://lists.apache.org/thread/m52jll26vc8g5jokbg0xt062o09wkghr"}],"source_lang":"en-US","title":"Apache Sling: Mehrere Schwachstellen","tracking":{"current_release_date":"2026-09-22T22:00:00.000+00:00","generator":{"date":"2026-09-23T11:34:27.620+00:00","engine":{"name":"BSI-WID","version":"1.6.0"}},"id":"WID-SEC-W-2026-3526","initial_release_date":"2026-09-22T22:00:00.000+00:00","revision_history":[{"date":"2026-09-22T22:00:00.000+00:00","number":"1","summary":"Initiale Fassung"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_version_range","name":"XSS <2.4.12","product":{"name":"Apache Sling XSS <2.4.12","product_id":"T060037"}},{"category":"product_version","name":"XSS 2.4.12","product":{"name":"Apache Sling XSS 2.4.12","product_id":"T060037-fixed","product_identification_helper":{"cpe":"cpe:/a:apache:sling:xss__2.4.12"}}},{"category":"product_version_range","name":"Security Bundle <1.3.12","product":{"name":"Apache Sling Security Bundle <1.3.12","product_id":"T060039"}},{"category":"product_version","name":"Security Bundle 1.3.12","product":{"name":"Apache Sling Security Bundle 1.3.12","product_id":"T060039-fixed","product_identification_helper":{"cpe":"cpe:/a:apache:sling:security_bundle__1.3.12"}}}],"category":"product_name","name":"Sling"}],"category":"vendor","name":"Apache"}]},"vulnerabilities":[{"cve":"CVE-2026-73192","product_status":{"known_affected":["T060039","T060037"]},"release_date":"2026-09-22T22:00:00.000+00:00","title":"CVE-2026-73192"},{"cve":"CVE-2026-91852","product_status":{"known_affected":["T060039","T060037"]},"release_date":"2026-09-22T22:00:00.000+00:00","title":"CVE-2026-91852"},{"cve":"CVE-2026-91928","product_status":{"known_affected":["T060039","T060037"]},"release_date":"2026-09-22T22:00:00.000+00:00","title":"CVE-2026-91928"},{"cve":"CVE-2026-91999","product_status":{"known_affected":["T060039","T060037"]},"release_date":"2026-09-22T22:00:00.000+00:00","title":"CVE-2026-91999"},{"cve":"CVE-2026-92001","product_status":{"known_affected":["T060039","T060037"]},"release_date":"2026-09-22T22:00:00.000+00:00","title":"CVE-2026-92001"},{"cve":"CVE-2026-94243","product_status":{"known_affected":["T060039","T060037"]},"release_date":"2026-09-22T22:00:00.000+00:00","title":"CVE-2026-94243"},{"cve":"CVE-2026-94251","product_status":{"known_affected":["T060039","T060037"]},"release_date":"2026-09-22T22:00:00.000+00:00","title":"CVE-2026-94251"}]}