CVE-2025-54253: Adobe Experience Manager Forms Code Execution Vulnerability
Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.
Other sources
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
If running Adobe Experience Manager (AEM) Forms version 6.5.23 or earlier (these are identified as affected), discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54253?
CVE-2025-54253 has a high severity level due to its potential for arbitrary code execution.
How do I fix CVE-2025-54253?
To fix CVE-2025-54253, upgrade Adobe Experience Manager to version 6.5.24 or later.
What versions of Adobe Experience Manager are affected by CVE-2025-54253?
Adobe Experience Manager versions 6.5.23 and earlier are affected by CVE-2025-54253.
What type of vulnerability is CVE-2025-54253?
CVE-2025-54253 is a misconfiguration vulnerability that allows for arbitrary code execution.
Can CVE-2025-54253 be exploited remotely?
Yes, CVE-2025-54253 can be exploited remotely by attackers to bypass security mechanisms.