CVE-2025-54254 – Unauthenticated XXE – Adobe Experience Manager Forms on JEE

ISGroup Cybersecurity

Adobe Experience Manager (AEM) Forms on Java EE is an enterprise platform for creating and managing secure, form-based processes. CVE-2025-54254 is a critical vulnerability that allows unauthenticated attackers to read files from the compromised server. It affects AEM Forms on JEE in versions 6.5.23.0 and earlier. The vulnerability has been added to the CISA database, and a public proof-of-concept is available.

Date2025-08-13 19:10:58
Information
  • Public Proof of Concept

Technical Summary

The vulnerability is caused by improper restriction of XML External Entity (XXE) processing in a SOAP-based web service component of AEM Forms on JEE. An attacker can send a specially crafted XML payload containing a reference to an external entity to the vulnerable endpoint /edcws/services/urn:EDCLicenseService (and potentially other SOAP endpoints). Because the XML parser processes these external entities, the attacker can retrieve arbitrary files from the server’s file system or configuration files containing sensitive data.
This flaw is exploitable over the network without authentication or user interaction.

Recommendations

  1. Apply the patch immediately: Update to AEM Forms on JEE version 6.5.0-0108 as indicated in Adobe’s APSB25-82 advisory.
  2. Restrict access: Limit exposure of SOAP service endpoints to trusted networks or VPN connections until the patch is applied.
  3. Monitor logs: Check server logs for suspicious XML POST requests to /edcws/services/urn:EDCLicenseService or similar SOAP services.
  4. Backup before changes: Create backups of the CRX repository, form archive, and related configurations before applying the update.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert