CVE-2023-40051
18.01.2024, 15:15
This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0.An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE. If the upload contains a payload that can further exploit the server or its network, the launch of a larger scale attack may be possible.Enginsight
Vendor | Product | Version |
---|---|---|
progress | openedge | 11.7 ≤ 𝑥 < 11.7.18 |
progress | openedge | 12.2 ≤ 𝑥 < 12.2.13 |
progress | openedge_innovation | 𝑥 < 12.8.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References