CVE-2025-45854CRITICAL 10.0EPSS p87.5%

CVE-2025-45854CVE-2025-45854

Description

/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.

Scoring

CVSS 3.110.0 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS3.16% probability of exploitation · percentile 87.5% · 2026-10-05T12:00:23Z
Published2025-06-03
Last modified2025-08-26

Underlying weaknesses· 1

CWE-862

References

  1. https://gist.github.com/Cafe-Tea/bc14b38f4bfd951de2979a24c3358460
  2. https://gitee.com/jehc/JEHC-BPM
  3. https://web.archive.org/web/20250604134020/https://gist.github.com/Cafe-Tea/bc14b38f4bfd951de2979a24c3358460/revisions

1

TypeTargetConfidenceTier
WeaknessMissing Authorizationcwe-8620%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-29902
CVE
CVE-2025-59458
CVE
CVE-2025-60801
CVE
Adobe Experience Manager Forms Code Execution Vulnerability
CVE
CVE-2025-59706
CVE
CVE-2026-3207
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.