VendorsProgressopenedgeall versions
Vulnerabilities

Progress Openedge

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2007-2417
Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6.1, SecurID Appliance 2.0, ACE/Server 5.2, and possibly other products, allows remote attackers to execute arbitrary code via crafted packets. NOTE: this issue might overlap CVE-2007-3491.
Published 2007-07-15 · Modified
10.0EPSS 0.162
CVE-2024-1403
Authentication Bypass in OpenEdge Authentication Gateway and AdminServer
Published 2024-02-27 · Analyzed
10.0EPSS 0.033
CVE-2023-40051
Progress Application Server (PAS) for OpenEdge File Upload via Directory Traversal
Published 2024-01-18 · Modified
9.9EPSS 0.006
CVE-2015-9245
Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931.
Published 2017-10-31 · Modified
9.8EPSS 0.019
CVE-2024-7345
Direct local client connections to MS Agents can bypass authentication
Published 2024-09-03 · Analyzed
9.6EPSS 0.006
CVE-2023-34203
In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x before 12.2.12, and 12.3.x through 12.6.x before 12.7.
Published 2023-06-23 · Modified
8.8EPSS 0.011
CVE-2024-7654
Unauthenticated Content Injection in OpenEdge Management web interface via ActiveMQ discovery service
Published 2024-09-03 · Analyzed
8.3EPSS 0.003
CVE-2022-29849
In Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were susceptible to privilege escalation. If exploited, a local attacker could elevate their privileges and compromise the affected system.
Published 2022-05-01 · Modified
7.8EPSS 0.003
CVE-2007-3491
Buffer overflow in _mprosrv in Progress Software OpenEdge before 9.1E0422, and 10.x before 10.1B01, allows remote attackers to have an unknown impact via a malformed TCP/IP message.
Published 2007-06-29 · Modified
7.5EPSS 0.025
CVE-2023-40052
Progress Application Server (PAS) for OpenEdge Denial of Service
Published 2024-01-18 · Modified
7.5EPSS 0.006
CVE-2024-7346
Client connections using default TLS certificates from OpenEdge may bypass TLS host name validation
Published 2024-09-03 · Analyzed
7.2EPSS 0.002
CVE-2014-8555
Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the selection parameter.
Published 2014-11-12 · Modified
5.01 PoCEPSS 0.075