Absolute Secure Access Management Console Deserialization Vulnerability Allowing Code Execution

Vulnerability

A deserialization vulnerability has been identified in the management console of Absolute Secure Access, affecting versions after 12.00 and prior to 13.56. This vulnerability allows attackers with administrative access to the console to manipulate unsafe content, leading to execution in the console's security context. The vulnerability arises from insufficient input validation, with a low attack complexity and no user interaction required. While the vulnerability has a low impact on confidentiality, it significantly compromises integrity. Additionally, there is minimal impact on the confidentiality and integrity of subsequent systems, with no effect on their availability.

Impact

Exploitation of this vulnerability allows for unauthorized deserialization and execution of content in the management console's security context, potentially leading to unauthorized actions or access within the application.

Added: Jul 31, 2025, 12:21 AM
Updated: Jul 31, 2025, 12:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
2.8
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.