8.4
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Description
It was possible to perform Remote Command Execution (RCE) via Java
RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and
execute OS commands under the delegated authority of the AdminServer process. An RMI interface permitted manipulation of a configuration
property with inadequate input validation leading to OS command injection.
RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and
execute OS commands under the delegated authority of the AdminServer process. An RMI interface permitted manipulation of a configuration
property with inadequate input validation leading to OS command injection.
Basic Information
ID
CVE-2025-7388
Source
ProgressSoftware
Published
Sep 4, 2025 at 13:01
Affected Product
Vendor
Progress Software Corporation
Product
OpenEdge
Version
OpenEdge 12.2.0
Affected Versions
Progress Software Corporation OpenEdge OpenEdge 12.2.0
Progress Software Corporation OpenEdge OpenEdge 12.8.0
Progress Software Corporation OpenEdge OpenEdge 12.8.0