CVE-2025-54253
Description
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
Summary dbcve.org
Adobe Experience Manager versions 6.5.23 and earlier contain a misconfiguration that allows attackers to bypass security mechanisms and achieve arbitrary code execution. The vulnerability requires no user interaction and involves a scope change, indicating the attack can impact components beyond the vulnerable AEM instance.
Mitigation
Update Adobe Experience Manager to a version newer than 6.5.23 to remediate this vulnerability. Review AEM security configurations and audit for any unauthorized changes.