In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x before 12.2.12, and 12.3.x through 12.6.x before 12.7.
References
Link | Resource |
---|---|
https://www.progress.com/openedge | Product |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-06-23 20:15
Updated : 2023-07-05 13:29
NVD link : CVE-2023-34203
Mitre link : CVE-2023-34203
CVE.ORG link : CVE-2023-34203
JSON object : View
Products Affected
progress
- openedge_management
- openedge
- openedge_explorer
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')