PT-2025-31949 · Adobe · Experience Manager

Adam Kues

+1

·

Published

2025-08-05

·

Updated

2026-01-05

·

CVE-2025-54253

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Experience Manager versions 6.5.23 and earlier
Description Adobe Experience Manager versions 6.5.23 and earlier are affected by a misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code without user interaction. Exploitation of this issue changes the scope of access. This vulnerability is actively being exploited and a public proof-of-concept is available. The vulnerability is related to a misconfigured servlet that evaluates unvalidated OGNL expressions, potentially enabling attackers to execute arbitrary commands. The vulnerability is present when the Struts development mode is enabled.
Recommendations Update Adobe Experience Manager to version 6.5.0-0108 or later. Disable the development mode (
devMode
) immediately.

Exploit

Fix

RCE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-09420
CVE-2025-54253

Affected Products

Experience Manager