CVE-2025-54086
BaseFortify
Publication date: 2025-10-02
Last updated on: 2025-10-16
Assigner: NetMotion Software
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| absolute | secure_access | to 14.10 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access before version 14.10. It allows attackers who have access to the local file system to read the Java keystore file. The attack is low complexity, requires low privileges, and no user interaction.
How can this vulnerability impact me? :
This vulnerability can impact confidentiality by allowing unauthorized reading of the Java keystore file, potentially exposing sensitive cryptographic keys. However, the impact to confidentiality is considered low, and there is no impact on integrity or availability.