Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-34320— BASIS BBj < 25.00 Unauthenticated Arbitrary File Read RCE

Quick assessment

Affected
BASIS International Ltd. BASIS BBj
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

BASIS BBj是美国BASIS公司的一个语言环境。 BASIS BBj 25.00之前版本存在安全漏洞,该漏洞源于未正确验证或规范化输入路径段,可能导致目录遍历攻击。

AI Predicted 9.8 Difficulty: Easy EPSS 0.81% · P54

Affected Version Matrix 1

VendorProduct Version RangeStatus
BASIS International Ltd. BASIS BBj < 25.00 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-34320

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
BASIS BBj < 25.00 Unauthenticated Arbitrary File Read RCE
Source: CVE Program / CVE List V5
Vulnerability Description
BASIS BBj versions prior to 25.00 contain a Jetty-served web endpoint that fails to properly validate or canonicalize input path segments. This allows unauthenticated directory traversal sequences to cause the server to read arbitrary system files accessible to the account running the service. Retrieved configuration artifacts may contain account credentials used for BBj Enterprise Manager; possession of these credentials enables administrative access and use of legitimate management functionality that can result in execution of system commands under the service account. Depending on the operating system and the privileges of the BBj service account, this issue may also allow access to other sensitive files on the host, including operating system or application data, potentially exposing additional confidential information.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5
Vulnerability Title
BASIS BBj 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
BASIS BBj是美国BASIS公司的一个语言环境。 BASIS BBj 25.00之前版本存在安全漏洞,该漏洞源于未正确验证或规范化输入路径段,可能导致目录遍历攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
BASIS International Ltd. BASIS BBj 0 ~ 25.00 -

II. Public POCs for CVE-2025-34320

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-34320

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-34320

No comments yet


Leave a comment