QID 731217
Date Published: 2024-03-01
QID 731217: Progress OpenEdge Authentication Gateway and AdminServer Authentication Bypass Vulnerability
Progress OpenEdge Authentication Gateway (OEAG) configured with an OpenEdge Domain that uses the OS local authentication provider to grant user-id and password logins. This could lead to bypass authentication based on a failure to properly handle username and password, leading to unauthorized access without proper authentication.
Affected Versions:
- OpenEdge LTS versions prior to Update 11.7.19
- OpenEdge LTS versions prior to Update 12.2.14
- OpenEdge LTS versions prior to Update 12.8.1
QID Detection Logic (Un-Authenticated)
This QID sends GET request to check version of OpenEdge.
QID Detection Logic (Authenticated):
Windows: This QID checks for the file vulnerable version of Progress OpenEdge
Linux: This QID checks for installed Progress OpenEdge version using "/usr/dlc/bin/showvers" or "$DLC/bin/showvers $DLC"
Successful exploitation of this vulnerability could allow remote, unauthenticated attackers to bypass authentication mechanism and execute arbitrary code on the target system, potentially leading to complete system compromise.
CVEs related to QID 731217
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 000253075 |
|