Command Injection Vulnerability in Tyler Technologies ERP Pro 9 SaaS
CVE-2025-55077

5.3MEDIUM

Key Information:

Vendor
CVE Published:
7 August 2025

What is CVE-2025-55077?

An authenticated user of Tyler Technologies ERP Pro 9 SaaS can exploit a command injection vulnerability that allows them to escape the application and execute restricted operating system commands within the remote Microsoft Windows environment. This issue provides attackers with the ability to execute commands with the privileges of the authenticated user. In response, Tyler Technologies implemented hardened remote Windows environment settings to safeguard all customer environments starting from August 1, 2025.

Affected Version(s)

ERP Pro 9 SaaS 0 < 2025-08-01

ERP Pro 9 SaaS 2025-08-01

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shawn Plowman, Brookings County
.
CVE-2025-55077 : Command Injection Vulnerability in Tyler Technologies ERP Pro 9 SaaS