CVE-2025-45854CRITICAL 10.0EPSS p83.9%

CVE-2025-45854CVE-2025-45854

Description

/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.

Scoring

CVSS 3.110.0 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS2.69% probability of exploitation · percentile 83.9% · 2026-06-19T12:03:05Z
Published2025-06-03
Last modified2025-08-26

Underlying weaknesses· 1

CWE-862

References

  1. https://gist.github.com/Cafe-Tea/bc14b38f4bfd951de2979a24c3358460
  2. https://gitee.com/jehc/JEHC-BPM
  3. https://web.archive.org/web/20250604134020/https://gist.github.com/Cafe-Tea/bc14b38f4bfd951de2979a24c3358460/revisions

1

TypeTargetConfidenceTier
WeaknessMissing Authorizationcwe-8620%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-29902
CVE
CVE-2025-59458
CVE
CVE-2025-60801
CVE
Adobe Experience Manager Forms Code Execution Vulnerability
CVE
CVE-2025-59706
CVE
CVE-2026-3207
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.