Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-9245


Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931.


Published

2017-10-31T07:29:00.190

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application progress openedge 10.2a Yes
Application progress openedge 10.2b Yes
Application progress openedge 10.2b07 Yes
Application progress openedge 10.2b08 Yes
Application progress openedge 11.0 Yes
Application progress openedge 11.1 Yes
Application progress openedge 11.2 Yes
Application progress openedge 11.3 Yes
Application progress openedge 11.4 Yes
Application progress openedge 11.5 Yes

References