PT-2024-2025 · Progress · Openedge Authentication Gateway+1

Published

2024-02-27

·

Updated

2025-09-09

·

CVE-2024-1403

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEdge Authentication Gateway and AdminServer versions prior to 11.7.19, 12.2.14, 12.8.1
Description The issue is an authentication bypass vulnerability based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication. This vulnerability allows an attacker to gain unauthorized access to various OpenEdge components, including sensitive databases. It is estimated that over 7,500 services are potentially affected. A proof-of-concept exploit has been released, and users are advised to update to supported versions as soon as possible.
Recommendations To resolve the issue for each affected version, update OpenEdge Authentication Gateway and AdminServer to versions 11.7.19, 12.2.14, or 12.8.1. As a temporary workaround, consider restricting access to the vulnerable components until a patch is applied. Additionally, enable automatic software updates, use strong passwords and two-factor authentication, and be cautious when working online. Regularly back up data and do not ignore updates.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-01890
CVE-2024-1403

Affected Products

Server Admin
Openedge Authentication Gateway