PT-2026-32624 · Progress · Openedge

Published

2026-04-14

·

Updated

2026-04-19

·

CVE-2025-7389

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenEdge (affected versions not specified)
Description A flaw in the AdminServer component allows authenticated users to gain OS-level access to the server by adopting the authority of the AdminServer process. This allows users to read arbitrary files on the host system by misusing the setFile() and openFile() functions exposed through the Remote Method Invocation (RMI) interface, which is a mechanism that allows an object residing in one Java virtual machine to invoke methods on an object residing in another. Access is limited by the OS-level privileges granted to the AdminServer and the user's access to these methods via RMI.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7389

Affected Products

Openedge