CVE-2024-1403

In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified.  The vulnerability is a bypass to authentication based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication.  
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:openedge:*:*:*:*:lts:*:*:*
cpe:2.3:a:progress:openedge:*:*:*:*:lts:*:*:*
cpe:2.3:a:progress:openedge:*:*:*:*:lts:*:*:*

History

11 Feb 2025, 17:40

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://community.progress.com/s/article/Important-Critical-Alert-for-OpenEdge-Authentication-Gateway-and-AdminServer - () https://community.progress.com/s/article/Important-Critical-Alert-for-OpenEdge-Authentication-Gateway-and-AdminServer - Vendor Advisory
References () https://www.progress.com/openedge - () https://www.progress.com/openedge - Product
CPE cpe:2.3:a:progress:openedge:*:*:*:*:lts:*:*:*
First Time Progress
Progress openedge

Information

Published : 2024-02-27 16:15

Updated : 2025-02-11 17:40


NVD link : CVE-2024-1403

Mitre link : CVE-2024-1403

CVE.ORG link : CVE-2024-1403


JSON object : View

Products Affected

progress

  • openedge
CWE
CWE-305

Authentication Bypass by Primary Weakness

NVD-CWE-noinfo