PT-2026-32624 · Progress · Openedge
Published
2026-04-14
·
Updated
2026-04-19
·
CVE-2025-7389
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenEdge (affected versions not specified)
Description
A flaw in the AdminServer component allows authenticated users to gain OS-level access to the server by adopting the authority of the AdminServer process. This allows users to read arbitrary files on the host system by misusing the
setFile() and openFile() functions exposed through the Remote Method Invocation (RMI) interface, which is a mechanism that allows an object residing in one Java virtual machine to invoke methods on an object residing in another. Access is limited by the OS-level privileges granted to the AdminServer and the user's access to these methods via RMI.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openedge