Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-1403


In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified.  The vulnerability is a bypass to authentication based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication.  


Published

2024-02-27T16:15:45.643

Last Modified

2025-02-11T17:40:59.267

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 10.0 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-305
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application progress openedge < 11.7.19 Yes
Application progress openedge < 12.2.14 Yes
Application progress openedge < 12.8.1 Yes

References