CVE-2025-60805
7.5BESSystem · BES Application Server
BESSystem BES Application Server through 9.5.x allows unauthorized attackers to obtain sensitive information via the pre-resource configuration in bes-web.xml.
Executive summary
A critical information disclosure vulnerability in BESSystem BES Application Server allows unauthenticated attackers to remotely access sensitive system data.
Vulnerability
This vulnerability is an information disclosure flaw that occurs because the pre-resource option within bes-web.xml is incorrectly configured, allowing unauthenticated remote attackers to bypass access controls and retrieve sensitive information.
Business impact
The ability for an unauthenticated attacker to remotely extract sensitive information poses a significant risk to data confidentiality. With a CVSS score of 7.5, this high-severity vulnerability could lead to the exposure of proprietary data, credentials, or system configurations, potentially facilitating further network compromise or regulatory non-compliance.
Remediation
Immediate Action: Review the configuration of bes-web.xml to disable or restrict access to the pre-resource option, as no vendor patch is currently confirmed.
Proactive Monitoring: Monitor server access logs for anomalous requests directed at the bes-web.xml configuration or unexpected data retrieval patterns.
Compensating Controls: Deploy a Web Application Firewall (WAF) to filter and block unauthorized requests targeting the vulnerable application server endpoints.
Exploitation status
Public Exploit Available: Yes — a public proof-of-concept exists via the referenced GitHub Gist.
Analyst recommendation
Given the high CVSS score and the public availability of a proof-of-concept, organizations running BES Application Server must treat this as a priority. Immediately audit your current deployments for the vulnerable configuration and apply restrictive access controls to mitigate the risk of unauthorized data exfiltration until a formal vendor update is verified.