PT-2025-31455 · Absolute · Absolute Secure Access
Published
2025-07-30
·
Updated
2025-08-05
·
CVE-2025-49083
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Absolute Secure Access versions 12.01 through 13.55
Description
The management console of Absolute Secure Access is susceptible to an issue where attackers possessing administrative privileges can trigger the deserialization and execution of unsafe content within the console's security context. The attack requires low complexity and no user interaction. The confidentiality impact is low, while the integrity impact is high. The confidentiality and integrity of subsequent systems are also potentially impacted, but availability remains unaffected.
Recommendations
Update Absolute Secure Access to version 13.56 or later.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Absolute Secure Access