CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another administrator’s access to the console. The attack complexity is low; there are no attack requirements. Privileges required to execute the attack are high and the victim must actively participate in the attack sequence. There is no impact to confidentiality or availability, there is a low impact to integrity.
History

Fri, 03 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Oct 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Absolute
Absolute secure Access
Vendors & Products Absolute
Absolute secure Access

Thu, 02 Oct 2025 20:30:00 +0000

Type Values Removed Values Added
Description CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another administrator’s access to the console. The attack complexity is low; there are no attack requirements. Privileges required to execute the attack are high and the victim must actively participate in the attack sequence. There is no impact to confidentiality or availability, there is a low impact to integrity.
Title Cross-site Scripting vulnerability in Secure Access prior to 14.10
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published: 2025-10-02T20:15:09.464Z

Updated: 2025-10-03T14:59:45.131Z

Reserved: 2025-07-16T17:10:03.453Z

Link: CVE-2025-54089

cve-icon Vulnrichment

Updated: 2025-10-03T14:59:35.793Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-02T21:16:00.860

Modified: 2025-10-06T14:57:05.000

Link: CVE-2025-54089

cve-icon Redhat

No data.