CVE Field Guide
About Us
CVE-2025-45854
PUBLISHED
Assigner:
mitre
Reserved:
22.04.2025
Published:
03.06.2025
Updated:
04.06.2025
/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.
Metrics
CVSS 3.1
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score:
10
CVSS score
10
Attack Vector
Network
Scope
Changed
Attack Complexity
Low
Confidentiality Impact
High
Privileges Required
None
Integrity Impact
High
User Interaction
None
Availability Impact
High
CVSS 3.1
Product Status
Vendor
JEHc
Product
JEHC-BPM
Versions
Default:
unknown
Version 2.0.1 is affected
References
https://gitee.com/jehc/JEHC-BPM
https://gist.github.com/Cafe-Tea/bc14b38f4bfd951de2979a24c3358460
https://web.archive.org/web/20250604134020/https://gist.github.com/Cafe-Tea/bc14b38f4bfd951de2979a24c3358460/revisions
Problem Types
CWE-862 Missing Authorization
CWE