CVE-2025-45854: Jehc Jehc-Bpm

Critical severity, CVSS 10.0. EPSS: 3.2% chance of exploitation in the next 30 days.

/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.

Affected products

  • Jehc Jehc-Bpm: up to and including 2.0.1

Published 2025-06-03. Last modified 2026-06-17.