Remote Command Execution Vulnerability in OpenEdge AdminServer by Progress Software
CVE-2025-7388

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-7388?

A vulnerability has been identified in the OpenEdge AdminServer that allows authenticated users to perform Remote Command Execution (RCE) through the Java RMI interface. This weakness arises from insufficient input validation, enabling users to manipulate configuration properties and inject OS commands. Consequently, this can lead to unauthorized command execution under the privileges of the AdminServer process, posing significant security risks.

Affected Version(s)

OpenEdge Windows OpenEdge 12.2.0 < 12.2.18

OpenEdge Windows OpenEdge 12.8.0 < 12.8.8

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7388 : Remote Command Execution Vulnerability in OpenEdge AdminServer by Progress Software