CVE-2025-57644
Last modified
CVE-2025-57644 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. In addition, improper input validation allows for arbitrary file write and server-side request forgery (SSRF), enabling interaction with internal or external systems. Successful exploitation can lead to full server compromise, unauthorized access to sensitive data, and further network exploitation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Accela | Automation Platform | 22.2.3.0.230103 |
References
- https://medium.com/@anvarkh/cve-2025-57644-remote-code-execution-ssrf-in-accela-eedc6bc4adfbMitigation, Third Party Advisory
- https://www.accela.comProduct
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-57644?
How severe is CVE-2025-57644?
How do I fix CVE-2025-57644?
Are you affected by CVE-2025-57644?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
