QID 379310
Date Published: 2024-02-01
QID 379310: Progress OpenEdge Multiple Vulnerabilities (000239394,000240764)
Accelerate Application Development with the Progress OpenEdge Integrated Development Environment.
Affected Version
Progress OpenEdge prior to 11.7.18
Progress OpenEdge 12.0.0 to 12.2.13
Progress OpenEdge prior to 12.8.0
QID Detection Logic (Authenticated):
Windows: This QID checks for the file vulnerable version of Progress OpenEdge
Linux: This QID checks for installed Progress OpenEdge version using "/usr/dlc/bin/showvers" or "$DLC/bin/showvers $DLC"
Successful exploitation of this vulnerability may allow an attacker to formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE.
Solution
Upgrade to latest version of OpenEdge.Refer to OpenEdge for details.
Vendor References
- PAS DOS -
community.progress.com/s/article/Important-Progress-OpenEdge-Product-Alert-for-Progress-Application-Server-for-OpenEdge-PASOE-Denial-of-Service-Vulnerability-in-WEB-Transport - Progress OpenEdge Security Adviosry -
community.progress.com/s/article/Important-Progress-OpenEdge-Critical-Alert-for-Progress-Application-Server-in-OpenEdge-PASOE-Arbitrary-File-Upload-Vulnerability-in-WEB-Transport
CVEs related to QID 379310
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Progress OpenEdge Security Adviosry |
|