S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Network Vulnerabilities·Updated Jul 29, 2025

CVE-2022-25237 Scanner

CVE-2022-25237 Scanner - Authentication/Authorization Bypass vulnerability in Bonita Web

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-25237
9.8
CVSS

Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no privileges can access privileged API endpoints. This can lead to remote code execution by abusing the privileged API actions.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Bonita Web is a popular open-source workflow and BPM (Business Process Management) platform developed by Bonitasoft. Organizations around the world utilize it to streamline workflows, automate processes, and manage complex business operations efficiently. The platform allows users to create and customize business applications easily through its intuitive graphical interface. Businesses from various industries employ Bonita Web to improve productivity and operational effectiveness. Its modular design and support for various extensions make it a versatile tool for digital transformation initiatives. As a widely-used solution, maintaining its security is vital to protect sensitive business operations and data.

The Authentication/Authorization Bypass vulnerability identified in Bonita Web 2021.2 poses significant risks by allowing attackers to perform unauthorized actions. This issue is due to inappropriate exclude patterns within the RestAPIAuthorizationFilter. It allows unauthenticated users to bypass security measures and gain access to privileged API endpoints. Attackers can exploit this vulnerability by appending specific patterns to the URL endpoints. Exploitation can lead to unauthorized data access and potential system manipulation.

Technical analysis of the vulnerability indicates that attackers can target specific API endpoints by leveraging URL patterns such as ;i18ntranslation or /../i18ntranslation/. Additionally, the affected endpoints may allow the upload of files, broadening the impact of the vulnerability. The issue is critically heightened by the ease of exploitation, as attackers do not require prior authentication or specialized knowledge.

If exploited by malicious individuals, this vulnerability could facilitate unauthorized access to critical system components, potentially leading to data breaches. Attackers might manipulate internal functionalities or upload malicious files, compromising the system's integrity. The ease of exploitation by bypassing authentication checks poses significant security risks, jeopardizing confidential data and sensitive business processes.

REFERENCES

Solution Advice
  • Upgrade Bonita Web to the latest version to mitigate known vulnerabilities, including this authorization bypass issue.
  • Implement additional access control measures to ensure authorized access only to sensitive API endpoints and resources.
  • Regularly audit and update security configurations to align with best practices.
  • Consider employing web application firewalls to further shield against unauthorized access attempts.
  • Engage in regular security assessments and vulnerability scanning to identify and address potential security weaknesses.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-25237 Scanner - Authentication/Authorization Bypass vulnerability in Bonita Web | S4E