CVE-2025-59595
- EPSS 0.04%
- Veröffentlicht 04.11.2025 22:46:38
- Zuletzt bearbeitet 01.12.2025 23:15:52
CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash.
CVE-2025-54089
- EPSS 0.03%
- Veröffentlicht 02.10.2025 20:15:09
- Zuletzt bearbeitet 16.10.2025 18:21:03
CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another administrator’s access to the console. The attack complexity is low; th...
CVE-2025-54088
- EPSS 0.03%
- Veröffentlicht 02.10.2025 20:10:52
- Zuletzt bearbeitet 16.10.2025 18:22:01
CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the console can redirect victims to an arbitrary URL. The attack complexity is low, attack requirements are present, no privileges are ...
CVE-2025-54087
- EPSS 0.03%
- Veröffentlicht 02.10.2025 20:05:38
- Zuletzt bearbeitet 16.10.2025 18:22:43
CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access server. The attack complexity i...
CVE-2025-54086
- EPSS 0.02%
- Veröffentlicht 02.10.2025 19:56:37
- Zuletzt bearbeitet 16.10.2025 18:23:17
CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10. Attackers with access to the local file system can read the Java keystore file. The attack complexity is low, there are...
CVE-2025-49082
- EPSS 0.04%
- Veröffentlicht 30.07.2025 23:45:30
- Zuletzt bearbeitet 05.08.2025 20:16:11
CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to ...
CVE-2025-54085
- EPSS 0.03%
- Veröffentlicht 30.07.2025 23:40:28
- Zuletzt bearbeitet 05.08.2025 20:03:18
CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to ...
CVE-2025-49084
- EPSS 0.06%
- Veröffentlicht 30.07.2025 23:36:17
- Zuletzt bearbeitet 05.08.2025 20:16:26
CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access can overwrite policy rules without the requisite permissions. The attack complexity is low, attack requ...
CVE-2025-49083
- EPSS 0.31%
- Veröffentlicht 30.07.2025 23:30:52
- Zuletzt bearbeitet 05.08.2025 20:16:17
CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with administrative access to the console can cause unsafe content to be deserialized and executed in the ...
CVE-2025-49081
- EPSS 0.08%
- Veröffentlicht 12.06.2025 17:25:47
- Zuletzt bearbeitet 17.06.2025 20:32:38
There is an insufficient input validation vulnerability in the warehouse component of Absolute Secure Access prior to server version 13.55. Attackers with system administrator permissions can impair the availability of the Secure Access administrativ...