CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access server. The attack complexity is high, there are no attack requirements, and user interaction is required. There is no direct impact to confidentiality, integrity, or availability. There is a low severity subsequent system impact to integrity.
History

Thu, 02 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Description CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access server. The attack complexity is high, there are no attack requirements, and user interaction is required. There is no direct impact to confidentiality, integrity, or availability. There is a low severity subsequent system impact to integrity.
Title Server-side request forgery in Secure Access
References
Metrics cvssV4_0

{'score': 1.8, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2025-10-02T20:05:38.092Z

Reserved: 2025-07-16T17:10:03.453Z

Link: CVE-2025-54087

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-02T20:15:32.830

Modified: 2025-10-02T20:15:32.830

Link: CVE-2025-54087

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.