CVE 8.2 HIGH

Unauthorized Arbitrary File Read via RMI in AdminServer Interface_CVE-2025-7389

8.2 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Description

A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server
through the adopted authority of the AdminServer process itself.  The delegated authority of the AdminServer could allow its users the ability to read arbitrary files on the host system through the misuse of the setFile() and openFile()
methods exposed through the RMI interface.  Misuse was limited only by OS-level authority of the AdminServer's elevated
privileges granted and the user's access to these methods enabled through RMI.  The exploitable methods have been removed thus eliminating their access through RMI or downstream of the RMI registry.

Basic Information

ID CVE-2025-7389
Source ProgressSoftware
Published Apr 14, 2026 at 13:12

Affected Product

Vendor Progress Software Corporation
Product OpenEdge
Version OpenEdge 12.2.0
Affected Versions Progress Software Corporation OpenEdge OpenEdge 12.2.0
Progress Software Corporation OpenEdge OpenEdge 12.8.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.