PT-2025-44196 · Bessystem · Application Server

Published

2025-10-28

·

Updated

2025-10-28

·

CVE-2025-60805

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions BESSystem BES Application Server versions through 9.5.x
Description An issue exists that could allow unauthorized attackers to obtain sensitive information. This is due to the “pre-resource” option within the bes-web.xml file.
Recommendations Versions through 9.5.x should be updated.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-60805

Affected Products

Application Server