VYPR

Openedge Management

by Progress (organisation)

CVEs (2)

  • CVE-2023-34203HigJun 23, 2023
    risk 0.57cvss 8.8epss 0.01

    In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x…

  • CVE-2024-7654HigSep 3, 2024
    risk 0.54cvss 8.3epss 0.00

    An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated.  Unauthorized access to the discovery service's UDP port allowed content injection into parts of the OEM web interface making it…