Shenzhen Dashi Tongzhou Information Technology AgileBPM SysToolsController.java parseStrByFreeMarker deserialization
Published Jun 5, 2025
5.3
MEDIUMCVSS 4.0
EPSS 0.51%
Description
A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected is the function parseStrByFreeMarker of the file /src/main/java/com/dstz/sys/rest/controller/SysToolsController.java. The manipulation of the argument str leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected products
-
Affected
- 2.0
- 2.1
- 2.2
- 2.3
- 2.4
- 2.5.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Shenzhen Dashi Tongzhou Information Technology | AgileBPM | unknown | Affected
|
- ≤ 2.5.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-17020 Advisory
- https://gitee.com/agile-bpm/agile-bpm-basic/issues/ICAQWG exploitissue-trackingIssue TrackingVendor Advisory
- https://vuldb.com/?ctiid.311166 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.311166 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.585127 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-17020 | Advisory | |
| https://gitee.com/agile-bpm/agile-bpm-basic/issues/ICAQWG | exploitissue-trackingIssue TrackingVendor Advisory | |
| https://vuldb.com/?ctiid.311166 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.311166 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.585127 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data