CVE-2025-60805

7.5

BESSystem · BES Application Server

BESSystem BES Application Server through 9.5.x allows unauthorized attackers to obtain sensitive information via the pre-resource configuration in bes-web.xml.

Executive summary

A critical information disclosure vulnerability in BESSystem BES Application Server allows unauthenticated attackers to remotely access sensitive system data.

Vulnerability

This vulnerability is an information disclosure flaw that occurs because the pre-resource option within bes-web.xml is incorrectly configured, allowing unauthenticated remote attackers to bypass access controls and retrieve sensitive information.

Business impact

The ability for an unauthenticated attacker to remotely extract sensitive information poses a significant risk to data confidentiality. With a CVSS score of 7.5, this high-severity vulnerability could lead to the exposure of proprietary data, credentials, or system configurations, potentially facilitating further network compromise or regulatory non-compliance.

Remediation

Immediate Action: Review the configuration of bes-web.xml to disable or restrict access to the pre-resource option, as no vendor patch is currently confirmed.

Proactive Monitoring: Monitor server access logs for anomalous requests directed at the bes-web.xml configuration or unexpected data retrieval patterns.

Compensating Controls: Deploy a Web Application Firewall (WAF) to filter and block unauthorized requests targeting the vulnerable application server endpoints.

Exploitation status

Public Exploit Available: Yes — a public proof-of-concept exists via the referenced GitHub Gist.

Analyst recommendation

Given the high CVSS score and the public availability of a proof-of-concept, organizations running BES Application Server must treat this as a priority. Immediately audit your current deployments for the vulnerable configuration and apply restrictive access controls to mitigate the risk of unauthorized data exfiltration until a formal vendor update is verified.

Sources