← Vulnerability feed

Vulnerability record · CVE-2024-1403 · published 27 February 2024

CVE-2024-1403: Progress openedge vulnerability

Progress · Openedge

In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified.  The vulnerability is a bypass to authentication based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication.  

9.8 CVSS 3.1 Critical EPSS 3.3% · top 11.9% CWE-305 · CWE-305
9.8CVSS 3.1 base score
3.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified.  The vulnerability is a bypass to authentication based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication.  

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-1403 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2417Progress openedge vulnerabilityHeap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6…EPSS 16%9.9CVE-2023-40051Progress openedge unrestricted file upload vulnerabilityThis issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases p…EPSS 0.56%9.8CVE-2015-9245Progress openedge improper access control vulnerabilityInsecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from wh…EPSS 1.9%9.6CVE-2024-7345Progress openedge code injection vulnerabilityLocal ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents o…EPSS 0.59%8.8CVE-2023-34203Progress openedge injection vulnerabilityIn Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a U…EPSS 1.1%7.8CVE-2022-29849Progress openedge vulnerabilityIn Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were susceptible to privilege escal…EPSS 0.28%7.5CVE-2023-40052Progress openedge memory buffer overflow vulnerabilityThis issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases p…EPSS 0.57%7.5CVE-2007-3491Progress openedge vulnerabilityBuffer overflow in _mprosrv in Progress Software OpenEdge before 9.1E0422, and 10.x before 10.1B01, allows remote attackers to have an unknown impact…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2024-1403), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.