QID 150819
Date Published: 2024-03-06
QID 150819: Progress OpenEdge Authentication Gateway Authentication Bypass Vulnerability (CVE-2024-1403)
OpenEdge Advanced Business Language, or OpenEdge ABL for short, is a business application development language created and maintained by Progress Software Corporation.
When the OpenEdge Authentication Gateway (OEAG) is configured with an OpenEdge Domain that uses the OS local authentication provider to grant user-id and password logins on operating platforms supported by active releases of OpenEdge, a vulnerability in the authentication routines may lead to unauthorized access on attempted logins.
Similarly, when an AdminServer connection is made by OpenEdge Explorer (OEE) and OpenEdge Management (OEM), it also utilizes the OS local authentication provider on supported platforms to grant user-id and password logins that may also lead to unauthorized login access.
Affected versions:
OpenEdge Release 11.7.18 and earlier
OpenEdge 12.2.13 and earlier
OpenEdge 12.8.0
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request and checks for vulnerable version of OpenEdge running on the target application.
Successful exploitation of this vulnerability could allow a remote attacker to access restricted resources by bypassing control checks.
CVEs related to QID 150819
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| OpenEdge |
|