← Vulnerability feed

Vulnerability record · CVE-2007-2417 · published 15 July 2007

CVE-2007-2417: Progress openedge vulnerability

Progress · Openedge

Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6.1, SecurID Appliance 2.0, ACE/Server 5.2, and possibly other products, allows remote attackers to execute arbitrary code via crafted packets. NOTE: this issue might overlap CVE-2007-3491.

10.0 CVSS 2.0 High EPSS 16% · top 3.2%
10.0CVSS 2.0 base score
16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6.1, SecurID Appliance 2.0, ACE/Server 5.2, and possibly other products, allows remote attackers to execute arbitrary code via crafted packets. NOTE: this issue might overlap CVE-2007-3491.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2417 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2023-40051Progress openedge unrestricted file upload vulnerabilityThis issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases p…EPSS 0.56%9.8CVE-2024-1403Progress openedge vulnerabilityIn OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentic…EPSS 3.3%9.8CVE-2015-9245Progress openedge improper access control vulnerabilityInsecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from wh…EPSS 1.9%9.6CVE-2024-7345Progress openedge code injection vulnerabilityLocal ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents o…EPSS 0.59%8.8CVE-2023-34203Progress openedge injection vulnerabilityIn Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a U…EPSS 1.1%7.8CVE-2022-29849Progress openedge vulnerabilityIn Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were susceptible to privilege escal…EPSS 0.28%7.8CVE-2007-2506Progress vulnerabilityWebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of servic…EPSS 4.0%7.5CVE-2023-40052Progress openedge memory buffer overflow vulnerabilityThis issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases p…EPSS 0.57%

Source: NIST National Vulnerability Database (record CVE-2007-2417), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.