Directory Traversal Vulnerability in BASIS BBj Web Service
CVE-2025-34320

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
20 November 2025

What is CVE-2025-34320?

BASIS BBj versions before 25.00 are susceptible to a directory traversal vulnerability due to a Jetty-served web endpoint that inadequately validates or canonicalizes input path segments. This flaw permits unauthenticated users to execute directory traversal sequences, allowing the server to read arbitrary system files accessible by the service account. Consequently, sensitive configuration files may be exposed, potentially revealing account credentials used for BBj Enterprise Manager. If compromised, these credentials facilitate administrative access and the execution of system commands under the service account. The impact of this issue may extend to access sensitive operating system or application data, further jeopardizing the confidentiality of information stored on the host system.

Affected Version(s)

BASIS BBj 0 < 25.00

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Victor A. Morales, Senior Pentester Team Leader, GMSecTec Inc.
Omar Crespo, Pentester, GMSecTec Inc.
.
CVE-2025-34320 : Directory Traversal Vulnerability in BASIS BBj Web Service