PT-2025-31949 · Adobe · Experience Manager

Adam Kues

+1

·

Published

2025-08-05

·

Updated

2025-10-28

·

CVE-2025-54253

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Experience Manager versions 6.5.23 and earlier
Description Adobe Experience Manager versions 6.5.23 and earlier are affected by a misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code without user interaction. Exploitation of this issue changes the scope of access. This vulnerability is actively being exploited and a public proof-of-concept exploit is available. The vulnerability is related to an exposed
/adminui/debug
servlet that evaluates unvalidated OGNL expressions, allowing attackers to execute arbitrary commands. The vulnerability is rated with a CVSS score of 10.0.
Recommendations Update Adobe Experience Manager to version 6.5.0-0108 or later. Disable the Struts2 development mode for admin functionalities. Restrict internet access to vulnerable systems. Audit systems for the presence of the vulnerable servlet.

Exploit

Fix

RCE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-09420
CVE-2025-54253

Affected Products

Experience Manager