NCSC-NL says Adobe fixed three high-severity flaws in Adobe Campaign Classic on August 27: two CVSS 10.0 server-side request forgery bugs and one CVSS 10.0 OS command injection bug, all usable without user interaction. The advisory says the issues can let an attacker run arbitrary code or operating-system commands on the Campaign Classic server.
The SSRF bug lets attacker-supplied input steer the server into making requests it should not make; the command-injection bugs let crafted input be treated as shell commands. Either way, the execution target is the Campaign Classic host itself, so compromise follows the privileges of the service account running it.
For teams running internet-facing Campaign Classic or a privileged service account behind it, the lasting exposure is not just the web app’s logic but the machine it sits on and whatever that machine can reach. The advisory does not give a remediation version, so the fix status has to be checked against Adobe’s updates, not inferred from the CVEs alone.