← Vulnerability feed

Vulnerability record · CVE-2014-8555 · published 12 November 2014

CVE-2014-8555: Progress openedge path traversal vulnerability

Progress · Openedge

Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the selection parameter.

5.0 CVSS 2.0 Medium EPSS 7.5% · top 5.7% CWE-22 · Path traversal
5.0CVSS 2.0 base score
7.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the selection parameter.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-8555 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2417Progress openedge vulnerabilityHeap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6…EPSS 16%9.9CVE-2023-40051Progress openedge unrestricted file upload vulnerabilityThis issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases p…EPSS 0.56%9.8CVE-2024-1403Progress openedge vulnerabilityIn OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentic…EPSS 3.3%9.8CVE-2015-9245Progress openedge improper access control vulnerabilityInsecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from wh…EPSS 1.9%9.6CVE-2024-7345Progress openedge code injection vulnerabilityLocal ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents o…EPSS 0.59%8.8CVE-2023-34203Progress openedge injection vulnerabilityIn Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a U…EPSS 1.1%7.8CVE-2022-29849Progress openedge vulnerabilityIn Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were susceptible to privilege escal…EPSS 0.28%7.5CVE-2023-40052Progress openedge memory buffer overflow vulnerabilityThis issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases p…EPSS 0.57%

Source: NIST National Vulnerability Database (record CVE-2014-8555), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.