Product
progress openedge
12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-7654
CVE-2024-7346
CVE-2024-7345
CVE-2024-1403
CVE-2023-40052
CVE-2023-40051
CVE-2023-34203
CVE-2022-29849
CVE-2015-9245
CVE-2014-8555
CVE-2007-2417
CVE-2007-3491
<= 11.7.19
An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery fea
<= 11.7.19
Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS
<= 11.7.18
Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Mul
< 11.7.19
In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge pr
>= 11.7 and < 11.7.18
This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and in
>= 11.7 and < 11.7.18
This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and in
< 11.7.16
In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role
>= 11.7 and < 11.7.14
In Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were susceptible
all versions
Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arb
all versions
Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attackers to rea
all versions
Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authenticatio
all versions
Buffer overflow in _mprosrv in Progress Software OpenEdge before 9.1E0422, and 10.x before 10.1B01, allows remote attackers to hav