C
VE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access server. The attack complexity is high, there are no attack requirements, and user interaction is required. There is no direct impact to confidentiality, integrity, or availability. There is a low severity subsequent system impact to integrity.
References
| Link | Resource |
|---|---|
| https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-54087 | Vendor Advisory |
Configurations
History
16 Oct 2025, 18:22
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* | |
| References | () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-54087 - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 2.6 |
| First Time |
Absolute
Absolute secure Access |
07 Oct 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-918 |
02 Oct 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-02 20:15
Updated : 2025-10-16 18:22
NVD link : CVE-2025-54087
Mitre link : CVE-2025-54087
CVE.ORG link : CVE-2025-54087
JSON object : View
Products Affected
CWE
CWE-918
Server-Side Request Forgery (SSRF)