PT-2025-35122 · Valtimo · Valtimo

Theo-Ritense

·

Published

2025-08-28

·

Updated

2025-08-28

·

CVE-2025-58059

CVSS v3.1
9.1
VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

Valtimo versions prior to 12.16.0

Valtimo versions 13.0.0 through 13.1.1

Description:

Valtimo is a platform for Business Process Automation. Administrators with the ability to create, modify, and execute process definitions could gain access to sensitive data or resources. This includes running executables on the application host, inspecting and extracting data from the host environment or application properties, and accessing spring beans (application context, database pooling). To perform this attack, a user must be logged in with the admin role and possess knowledge of running scripts via the Camunda/Operator engine.

Recommendations:

Upgrade to Valtimo version 12.16.0 or later.

Upgrade to Valtimo version 13.1.2 or later.

If scripting is not required in any processes, disable it via the ProcessEngineConfiguration. Note that this workaround may cause unexpected side effects.

Fix

RCE

Information Disclosure

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-58059
GHSA-W48J-PP7J-FJ55

Affected Products

Valtimo