Jehc-Bpm · Jehc-Bpm · CVE-2025-45854
**Name of the Vulnerable Software and Affected Versions**
JEHC-BPM version 2.0.1
**Description**
The issue allows attackers to execute arbitrary code via uploading a crafted file to the "/server/executeExec" API endpoint. This is due to an arbitrary file upload vulnerability in the component.
**Recommendations**
For JEHC-BPM version 2.0.1, consider restricting access to the `/server/executeExec` API endpoint to minimize the risk of exploitation until a patch is available. Avoid using this endpoint with untrusted input to prevent arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.