CVE-2025-54086

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
02/10/2025
Last modified:
16/10/2025

Description

CVE-2025-54086 is an excess permissions vulnerability in the<br /> Warehouse component of Absolute Secure Access prior to version 14.10. Attackers<br /> with access to the local file system can read the Java keystore file. The<br /> attack complexity is low, there are no attack requirements, the privileges<br /> required are low and no user interaction is required. Impact to confidentiality<br /> is low, there is no impact to integrity or availability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* 14.10 (excluding)