CVE-2025-54087 is a server-side request forgery
vulnerability in Secure Access prior to version 14.10. Attackers with
administrative privileges can publish a crafted test HTTP request originating
from the Secure Access server. The attack complexity is high, there are no
attack requirements, and user interaction is required. There is no direct
impact to confidentiality, integrity, or availability. There is a low severity
subsequent system impact to integrity.
References
| Link | Resource |
|---|---|
| https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-54087 | Vendor Advisory |
Configurations
History
16 Oct 2025, 18:22
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-54087 - Vendor Advisory | |
| First Time |
Absolute
Absolute secure Access |
|
| CPE | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 2.6 |
07 Oct 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-918 |
02 Oct 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-02 20:15
Updated : 2025-10-16 18:22
NVD link : CVE-2025-54087
Mitre link : CVE-2025-54087
CVE.ORG link : CVE-2025-54087
JSON object : View
Products Affected
absolute
- secure_access
CWE
CWE-918
Server-Side Request Forgery (SSRF)
