CVE-2025-49084 – Absolute Secure Access Policy Rule Overwrite Vulnerability

The following table lists the changes that have been made to the
CVE-2025-49084 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jul. 31, 2025

    Action Type Old Value New Value
    Added Description CVE-2025-49084 is a vulnerability in the management console
    of Absolute Secure Access prior to version 13.56. Attackers with administrative
    access can overwrite policy rules without the requisite permissions. The attack
    complexity is low, attack requirements are present, privileges required are
    high and no user interaction is required. There is no impact to
    confidentiality, the impact to integrity is low, and there is no impact to
    availability. The impact to confidentiality and availability of subsequent systems
    is high and the impact to the integrity of subsequent systems is low.
    Added CVSS V4.0 AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:H/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added Reference https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-49084
Share the Post:

Related Posts