CVE-2025-49081
Severity CVSS v4.0:
MEDIUM
Type:
CWE-20
Input Validation
Publication date:
12/06/2025
Last modified:
17/06/2025
Description
There is an insufficient input validation vulnerability in the warehouse<br />
component of Absolute Secure Access prior to server version 13.55. Attackers<br />
with system administrator permissions can impair the availability of the Secure<br />
Access administrative UI by writing invalid data to the warehouse over the<br />
network. The attack complexity is low, there are no attack requirements,<br />
privileges required are high, and there is no user interaction required. There<br />
is no impact on confidentiality or integrity; the impact on availability is<br />
high.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
4.90
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* | 13.55 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



