CVE-2025-54254 Details
Description
Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed. Exploitation of this issue does not require user interaction.
A vulnerability allowing improper restriction of XML external entity references (XXE) has been identified in Adobe Experience Manager (AEM) Forms on Java Enterprise Edition (JEE) versions 6.5.23.0 and earlier. This XXE vulnerability could be exploited to read arbitrary files from the local file system, potentially allowing access to sensitive information. The exploitation of this vulnerability does not require user interaction.
Users are advised to update to Adobe Experience Manager (AEM) Forms on JEE version 6.5.0-0108. Update instructions are available on the Adobe Experience League website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| adobe experience manager forms | <= 6.5.23.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 2, 2025 | Modified Analysis | [email protected] |
| Aug 22, 2025 | CVE Modified | [email protected] |
| Aug 13, 2025 | Initial Analysis | [email protected] |
| Aug 5, 2025 | New CVE Received | [email protected] |