Vulnerability Description
An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-resource" option in bes-web.xml.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- http://bes.com
- http://www.bessystem.com/appserver/dtds/bes-web-app_2_5-0.dtd
- https://gist.github.com/Liu2000622/7a6294f7421ef50c378a456ca9494714
- https://www.bessystem.com/product/0ad9b8c4d6af462b8d15723a5f25a87d/info?p=101
FAQ
What is CVE-2025-60805?
CVE-2025-60805 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-resource" option in bes-web.xml.
How severe is CVE-2025-60805?
CVE-2025-60805 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-60805?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.