PT-2017-3369 · Progress · Openedge

Published

2017-10-31

·

Updated

2017-11-22

·

CVE-2015-9245

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Progress Software OpenEdge versions 10.2x through 11.x
Description The issue is related to an insecure default configuration that lacks proper access control, allowing unauthenticated remote attackers to load and execute malicious Java classes by specifying arbitrary URLs via port 20931. This can be exploited by a remote attacker using specially crafted URL addresses.
Recommendations For Progress Software OpenEdge versions 10.2x through 11.x, consider restricting access to port 20931 as a temporary workaround until a proper fix is available. Additionally, review and modify the default configuration to enforce proper access controls and prevent the execution of malicious Java classes.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00140
CVE-2015-9245

Affected Products

Openedge