CVE-2025-49081

Severity CVSS v4.0:
MEDIUM
Type:
CWE-20 Input Validation
Publication date:
12/06/2025
Last modified:
17/06/2025

Description

There is an insufficient input validation vulnerability in the warehouse<br /> component of Absolute Secure Access prior to server version 13.55. Attackers<br /> with system administrator permissions can impair the availability of the Secure<br /> Access administrative UI by writing invalid data to the warehouse over the<br /> network. The attack complexity is low, there are no attack requirements,<br /> privileges required are high, and there is no user interaction required. There<br /> is no impact on confidentiality or integrity; the impact on availability is<br /> high.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* 13.55 (excluding)