CVE 9.1 CRITICAL

Recoverable obfuscation using the OECH1 prefix encoding in OpenEdge_CVE-2025-8095

9.1 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/AU:Y/V:D/RE:M/U:Red

Description

The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications. OECH1 encodings should be considered exploitable and immediately replaced by any other supported prefix encoding, all of which are based on symmetric encryption.

AI Analysis

Recoverable obfuscation using the OECH1 prefix encoding in OpenEdge, allowing for potential exploitation due to weak cryptographic encoding.

Basic Information

ID CVE-2025-8095
Source ProgressSoftware
Published Apr 14, 2026 at 13:13

Affected Product

Vendor Progress Software Corporation
Product OpenEdge
Version 12.2.0
Affected Versions Progress Software Corporation OpenEdge 12.2.0
Progress Software Corporation OpenEdge 12.8.0

CWE Classification

AI Assessment

AI Score 9.1 / 10
AI Severity Critical
Vendor Progress Software Corporation
Product OpenEdge
Version 12.2.0, 12.8.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.