HIGH🇵🇱 Wersja polska

CVE-2025-54254

CVSS 8.6v3.1pub. 2025-08-05upd. 2025-10-02

Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed. Exploitation of this issue does not require user interaction.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
  • Adobe Experience Manager Forms

    APP
    Adobe
    ≤ 6.5.23.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XXE
CWE
References

Related vulnerabilities

CVE-2025-54253CRITICAL10.0⚠ KEVPL ✓same product

RCE przez błędną konfigurację w Adobe Experience Manager Forms

CVE-2020-9732CRITICAL9.0PL ✓same product

Adobe Experience Manager Forms — stored XSS w komponencie Sites

CVE-2020-9733HIGH7.5same product

An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions ...

CVE-2017-3067HIGH7.5same product

Adobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability resulting f...

CVE-2019-8089MEDIUM6.1same product

Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successfu...