CVE-2025-49084 is a vulnerability in the management console
of Absolute Secure Access prior to version 13.56. Attackers with administrative
access can overwrite policy rules without the requisite permissions. The attack
complexity is low, attack requirements are present, privileges required are
high and no user interaction is required. There is no impact to
confidentiality, the impact to integrity is low, and there is no impact to
availability. The impact to confidentiality and availability of subsequent systems
is high and the impact to the integrity of subsequent systems is low.
References
Link | Resource |
---|---|
https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-49084 | Vendor Advisory |
Configurations
History
05 Aug 2025, 20:16
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
References | () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-49084 - Vendor Advisory | |
CPE | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* | |
First Time |
Absolute
Absolute secure Access |
31 Jul 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE | CWE-276 |
31 Jul 2025, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-31 00:15
Updated : 2025-08-05 20:16
NVD link : CVE-2025-49084
Mitre link : CVE-2025-49084
CVE.ORG link : CVE-2025-49084
JSON object : View
Products Affected
absolute
- secure_access
CWE
CWE-276
Incorrect Default Permissions