[CIVN-2025-0165] Multiple Vulnerabilities in Adobe Experience Manager (AEM) Forms on Java Enter-prise Edition (JEE)
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Adobe Experience Manager (AEM) Forms on Java Enter-prise Edition (JEE)
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Adobe Experience Manager Forms on Java Enterprise Edition (JEE) versions 6.5.23.0 and prior
Overview
Multiple vulnerabilities have been reported in Adobe Experience Manager (AEM) Forms on Java Enterprise Edition (JEE), which could be exploited by a remote attacker to execute arbitrary code, bypass security mechanisms and access sensitive information on the targeted system.
Target Audience:
All end-user organizations and individuals using affected Adobe Experience Manager (AEM) Forms on Java Enterprise Edition (JEE) versions.
Risk Assessment:
High risk of unauthorized access to sensitive data and remote code execution.
Impact Assessment:
Potential for unauthorized access to sensitive information, execution of arbitrary code, privilege escalation and full system compromise.
Description
Adobe Experience Manager (AEM) is a digital experience platform used for managing content across web, mobile, and other channels.
Multiple vulnerabilities exist in Adobe Experience Manager (AEM) Forms on Java Enterprise Edition (JEE) due to improper restriction of XML external entity references (XXE) and insecure default configuration of security settings.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, bypass security mechanisms and access sensitive information on the targeted system.
Solution
Apply appropriate updates as mentioned in the Adobe Security Bulletin.
https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html
Vendor Information
Adobe
https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html
References
Adobe
https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html
CVE Name
CVE-2025-54253
CVE-2025-54254
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmiWBKwACgkQ3jCgcSdc
ys8HSA/9FWjoeEwbhJNecg+vNJExvTfd4XYrJwJi897D6af+MG3lG6+CSR/GETAN
UZY3hUY6mTaWg4ppkFw+cT4BcjMpZGWBaWDW3XWxcA2aMW3wNbSSTGnzP941Nhcf
alMMQ9ag+cVFVXf7maA/qCb5EJ+rdHLeiGeHWFI3n5DAEzwkgJVAMDyT+7hmiweY
pzumMjQoqqoCTZpZaqLMPV89qbxCfMATv5/QKdYI5b8D1sI9KpSubIQWPk3J6pMa
jSNfzcwO7JscZ+KCc6gsPBB0U6bo52/BrQggk9nePC/CZW/vnNL4feTBrNIQDErV
0Srd0a9hhho89XGBbaSHjtzVbvb7a6qdtU33oo31VB4+yxnkqKSlzZgHAhb06cpb
Cf+UG8LqDc6OzXkrxzjFP5FH7PdpKnF1k9yAvf7v+1aulZw9aPb/pdAIInCWGWD2
hAgpv7qHVlv06vjbzwqnGbVY8hgbG60ubXXVYVoihvp3DgK4saG+9n654C3mkV66
E95vCHdoEPuoRSLpv+5Qgo6L+X/WhdRVOuIy4J5Qm7M40MaH+EeYvkXS6Gsip0NY
bYAwiF1I4M9Q7TnX352pBVRQAAqROLNJnV+Dy+zR7QH5eM0/Q7+0JIJeIRb132oW
W8iJYBGYxhJgnGXd7chC8A1OH9/hGVNWcxLrIU0D7D9binyZ3gY=
=xeS6
—–END PGP SIGNATURE—–