Potential Code Injection Vulnerability in Multi-Session Agents on ABL Platforms

CVE-2024-7345
9.6CRITICAL

Key Information

Vendor
Progress
Status
Openedge
Vendor
CVE Published:
3 September 2024

Summary

Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents on supported OpenEdge LTS platforms up to OpenEdge LTS 11.7.18 and LTS 12.2.13 on all supported release platforms

Affected Version(s)

OpenEdge <= 11.7.19

OpenEdge <= 11.7.19

OpenEdge <= 12.2.14

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.