CVE-2023-40052

EUVD-2023-44659


This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0

. 

An attacker who can produce a malformed web request may cause the crash of a PASOE agent potentially disrupting the thread activities of many web application clients. Multiple of these DoS attacks could lead to the flooding of invalid requests as compared to the server’s remaining ability to process valid requests.





ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
progressopenedge
11.7 ≤
𝑥
< 11.7.18
progressopenedge
12.2 ≤
𝑥
< 12.2.13
progressopenedge_innovation
𝑥
< 12.8.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
progressopenedge
11.7 ≤
𝑥
< 11.7.18
ADP
progressopenedge
12.2.0 ≤
𝑥
< 12.2.13
ADP
progressopenedge_innovation
𝑥
< 12.8.0
ADP