logo

Proof-of-Concept Exploit Released for Progress Software OpenEdge Vulnerability

ID: a4de4aa6-913b-5e03-be9b-05cc0ec7836f

STIX ID: report--a4de4aa6-913b-5e03-be9b-05cc0ec7836f

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-03-11

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A critical authentication bypass (CVE-2024-1403) in Progress OpenEdge Authentication Gateway and AdminServer can incorrectly return authentication success for certain malformed credentials, enabling unauthorized access; the flaw affects several OpenEdge versions, has a CVSS of 10.0, and Horizon3.ai published a PoC. Progress released patched updates (11.7.19, 12.2.14, 12.8.1) and researchers note the potential for further exploitation including possible remote code execution with additional research.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.