CVE-2023-40051

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE. If the upload contains a payload that can further exploit the server or its network, the launch of a larger scale attack may be possible.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:openedge:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:openedge:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:progress:openedge_innovation:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-01-18 15:15

Updated : 2024-01-26 15:25


NVD link : CVE-2023-40051

Mitre link : CVE-2023-40051

CVE.ORG link : CVE-2023-40051


JSON object : View

Products Affected

progress

  • openedge
  • openedge_innovation
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type