Executive brief
A vulnerability exists in the BES Application Server, a Java-based middleware platform used to run enterprise applications. An unauthorized attacker can exploit a configuration flaw to bypass access controls and view sensitive files stored on the server. This could lead to the exposure of internal system data, configuration details, or other confidential information, potentially compromising the security of the hosted applications.
Technical details
An incorrect access control vulnerability exists in BES Application Server versions 9.5.x and earlier. The flaw resides in how the server handles 'pre-resource' and 'post-resource' mappings within the bes-web.xml configuration file. The server utilizes insufficient prefix-based matching when validating mapped resource paths. A remote, unauthenticated attacker can exploit this by crafting a URL with a prefix similar to an intended mount point, allowing them to bypass authorization checks and retrieve local files from the mapped resource directory. This results in sensitive information disclosure (CWE-200).
Affected products
- BESSystem (Beijing Baolande Software) BES Application Server thru 9.5.x
Timeline
- 2025-10-28: advisory: Initial NVD publication date