Lucene search

K
cveProgressSoftwareCVE-2023-40052
HistoryJan 18, 2024 - 3:15 p.m.

CVE-2023-40052

2024-01-1815:15:09
CWE-119
ProgressSoftware
web.nvd.nist.gov
15
cve
progress application server
pas
openedge
security vulnerability
dos
nvd

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

17.0%

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0

.

An attacker who can produce a malformed web request may cause the crash of a PASOE agent potentially disrupting the thread activities of many web application clients. Multiple of these DoS attacks could lead to the flooding of invalid requests as compared to the server’s remaining ability to process valid requests.

Affected configurations

Nvd
Node
progressopenedgeRange11.7–11.7.18
OR
progressopenedgeRange12.2–12.2.13
Node
progressopenedge_innovationRange<12.8.0
VendorProductVersionCPE
progressopenedge*cpe:2.3:a:progress:openedge:*:*:*:*:*:*:*:*
progressopenedge_innovation*cpe:2.3:a:progress:openedge_innovation:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "affected",
    "modules": [
      "Progress Application Server (PAS) for OpenEdge"
    ],
    "product": "OpenEdge",
    "vendor": "Progress Software Corporation",
    "versions": [
      {
        "lessThan": "11.7.18",
        "status": "affected",
        "version": "11.7.0",
        "versionType": "semver"
      },
      {
        "lessThan": "12.2.13",
        "status": "affected",
        "version": "12.2.0",
        "versionType": "semver"
      },
      {
        "lessThan": "12.8.0",
        "status": "affected",
        "version": "Innovation Releases",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

17.0%

Related for CVE-2023-40052