PT-2017-3369 · Progress · Openedge
Published
2017-10-31
·
Updated
2017-11-22
·
CVE-2015-9245
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Progress Software OpenEdge versions 10.2x through 11.x
Description
The issue is related to an insecure default configuration that lacks proper access control, allowing unauthenticated remote attackers to load and execute malicious Java classes by specifying arbitrary URLs via port 20931. This can be exploited by a remote attacker using specially crafted URL addresses.
Recommendations
For Progress Software OpenEdge versions 10.2x through 11.x, consider restricting access to port 20931 as a temporary workaround until a proper fix is available. Additionally, review and modify the default configuration to enforce proper access controls and prevent the execution of malicious Java classes.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openedge