Record summary

CVE-2025-54249 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate server-side requests and bypass security controls allowing unauthorized read access.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 16, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 9, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: affected

CVE ListThrough 6.5.23.0affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMAdobe Experience Manager ≤ 6.5.23.0 – SSRF

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass

Impact

Unauthenticated attackers can bypass security feature restrictions and force the server to make requests to arbitrary URLs, potentially enabling access to internal services and metadata endpoints.

Remediation

Upgrade Adobe Experience Manager to a version later than 6.5.23.0 that properly validates redirect URLs and implements SSRF protections.

AuthorsDhiyaneshDk, assetnote
Template tagscvecve2025adobeaemssrfoastoobvkevvuln
FOFA: body="/libs/granite/core/content/login.html"

Source: ProjectDiscovery

References

2