VendorsProgressopenedgeany version
Vulnerabilities

Progress Openedge any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-1403
Authentication Bypass in OpenEdge Authentication Gateway and AdminServer
Published 2024-02-27 · Analyzed
10.0EPSS 0.033
CVE-2023-40051
Progress Application Server (PAS) for OpenEdge File Upload via Directory Traversal
Published 2024-01-18 · Modified
9.9EPSS 0.006
CVE-2024-7345
Direct local client connections to MS Agents can bypass authentication
Published 2024-09-03 · Analyzed
9.6EPSS 0.006
CVE-2023-34203
In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x before 12.2.12, and 12.3.x through 12.6.x before 12.7.
Published 2023-06-23 · Modified
8.8EPSS 0.011
CVE-2024-7654
Unauthenticated Content Injection in OpenEdge Management web interface via ActiveMQ discovery service
Published 2024-09-03 · Analyzed
8.3EPSS 0.003
CVE-2022-29849
In Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were susceptible to privilege escalation. If exploited, a local attacker could elevate their privileges and compromise the affected system.
Published 2022-05-01 · Modified
7.8EPSS 0.003
CVE-2023-40052
Progress Application Server (PAS) for OpenEdge Denial of Service
Published 2024-01-18 · Modified
7.5EPSS 0.006
CVE-2024-7346
Client connections using default TLS certificates from OpenEdge may bypass TLS host name validation
Published 2024-09-03 · Analyzed
7.2EPSS 0.002