Логотип exploitDog
bind:CVE-2025-54254
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-54254

Количество 3

Количество 3

nvd логотип

CVE-2025-54254

6 месяцев назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed. Exploitation of this issue does not require user interaction.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-6hv6-fgh2-5mjv

6 месяцев назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system. Exploitation of this issue does not require user interaction.

CVSS3: 8.6
EPSS: Низкий
fstec логотип

BDU:2025-09480

6 месяцев назад

Уязвимость корпоративной платформы для создания, управления и обработки электронных форм, документов и бизнес-процессов Adobe Experience Manager (AEM) Forms on JEE, связанная с неверным ограничением XML-ссылок на внешние объекты, позволяющая нарушителю читать произвольные файлы

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-54254

Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed. Exploitation of this issue does not require user interaction.

CVSS3: 8.6
0%
Низкий
6 месяцев назад
github логотип
GHSA-6hv6-fgh2-5mjv

Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system. Exploitation of this issue does not require user interaction.

CVSS3: 8.6
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2025-09480

Уязвимость корпоративной платформы для создания, управления и обработки электронных форм, документов и бизнес-процессов Adobe Experience Manager (AEM) Forms on JEE, связанная с неверным ограничением XML-ссылок на внешние объекты, позволяющая нарушителю читать произвольные файлы

CVSS3: 8.6
0%
Низкий
6 месяцев назад

Уязвимостей на страницу