SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP Adobe Experience Manager remote code execution attempt
This rule looks for specially crafted inbound HTTP requests to the "/adminui/" endpoint on Adobe Experience Manager web applications that attempt to invoke the Struts2 devMode feature to execute arbitrary OGNL expressions. Attackers have been observed exploiting an authentication bypass vulnerability (CVE-2025-54253) to be able to invoke devMode functionality.
This rule fires on attempts to exploit a remote code execution vulnerability in Adobe Experience Manager web applications.
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
Rule Categories::Server::Web Applications
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
N/A
Not Applicable
CVE-2025-54253 |
Loading description
|