In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified. The vulnerability is a bypass to authentication based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication.
2024-02-27T16:15:45.643
2025-02-11T17:40:59.267
Analyzed
CVSSv3.1: 10.0 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | progress | openedge | < 11.7.19 | Yes |
Application | progress | openedge | < 12.2.14 | Yes |
Application | progress | openedge | < 12.8.1 | Yes |