Home

Description

An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-resource" option in bes-web.xml.

PUBLISHED Reserved 2025-09-26 | Published 2025-10-28 | Updated 2025-10-29 | Assigner mitre

References

bes.com

www.bessystem.com/appserver/dtds/bes-web-app_2_5-0.dtd

www.bessystem.com/...b8c4d6af462b8d15723a5f25a87d/info?p=101

gist.github.com/Liu2000622/7a6294f7421ef50c378a456ca9494714

cve.org (CVE-2025-60805)

nvd.nist.gov (CVE-2025-60805)

Download JSON