PT-2025-31949 · Adobe · Experience Manager
Adam Kues
+1
·
Published
2025-08-05
·
Updated
2026-01-05
·
CVE-2025-54253
CVSS v3.1
10
Critical
| AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Adobe Experience Manager versions 6.5.23 and earlier
Description
Adobe Experience Manager versions 6.5.23 and earlier are affected by a misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code without user interaction. Exploitation of this issue changes the scope of access. This vulnerability is actively being exploited and a public proof-of-concept is available. The vulnerability is related to a misconfigured servlet that evaluates unvalidated OGNL expressions, potentially enabling attackers to execute arbitrary commands. The vulnerability is present when the Struts development mode is enabled.
Recommendations
Update Adobe Experience Manager to version 6.5.0-0108 or later.
Disable the development mode (
devMode) immediately.Exploit
Fix
RCE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Experience Manager