Lucene search

K
cveMitreCVE-2023-34203
HistoryJun 23, 2023 - 8:15 p.m.

CVE-2023-34203

2023-06-2320:15:09
CWE-74
mitre
web.nvd.nist.gov
18
cve-2023-34203
openedge oem
openedge management
oee
openedge explorer
url injection
identity change
role membership
security vulnerability
admin escalation
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

50.4%

In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x before 12.2.12, and 12.3.x through 12.6.x before 12.7.

Affected configurations

Nvd
Node
progressopenedgeRange<11.7.16lts
OR
progressopenedgeRange12.012.2.12lts
OR
progressopenedgeRange12.312.7lts
OR
progressopenedge_explorerRange<12.7
OR
progressopenedge_managementRange<12.7
VendorProductVersionCPE
progressopenedge*cpe:2.3:a:progress:openedge:*:*:*:*:lts:*:*:*
progressopenedge_explorer*cpe:2.3:a:progress:openedge_explorer:*:*:*:*:*:*:*:*
progressopenedge_management*cpe:2.3:a:progress:openedge_management:*:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

50.4%

Related for CVE-2023-34203