CVE 8.4 HIGH

Authenticated Command Injection via configuration parameter manipulation in exposed RMI interface_CVE-2025-7388

8.4 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

Description

It was possible to perform Remote Command Execution (RCE) via Java
RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and
execute OS commands under the delegated authority of the AdminServer process.  An RMI interface permitted manipulation of a configuration
property with inadequate input validation leading to OS command injection.

Basic Information

ID CVE-2025-7388
Source ProgressSoftware
Published Sep 4, 2025 at 13:01

Affected Product

Vendor Progress Software Corporation
Product OpenEdge
Version OpenEdge 12.2.0
Affected Versions Progress Software Corporation OpenEdge OpenEdge 12.2.0
Progress Software Corporation OpenEdge OpenEdge 12.8.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.