Record summary

CVE-2025-45854 has a selected CVSS score of 10.0 (critical); EIP currently links 1 Nuclei template.

Description

/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 3, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List2.0.1affected

Nuclei templates

1
ProjectDiscoveryCRITICALJEHC-BPM - Remote Code ExecuteCVSS 10

A Remote Command Execution vulnerability in the component /server/executeExec of JEHC-BPM <= v2.0.1 allows attackers to execute arbitrary code. The vulnerability exists due to insufficient authorization checks in the executeExec endpoint which allows direct command execution.

Impact

Unauthenticated attackers can execute arbitrary operating system commands through the /server/executeExec endpoint due to missing authorization checks, achieving complete server compromise.

Remediation

Upgrade JEHC-BPM to a version later than 2.0.1 that implements proper authorization checks on the executeExec endpoint.

WeaknessesCWE-862CWE-434
Authorsritikchaddha
Template tagscvecve2025jehc-bpmrcevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
FOFA: body="JEHC"

Source: ProjectDiscovery

References

4