HIGH · 8.8

CVE-2023-34203

In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role memb...

Vulnerability Description

In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x before 12.2.12, and 12.3.x through 12.6.x before 12.7.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ProgressOpenedge< 11.7.16
ProgressOpenedge Explorer< 12.7
ProgressOpenedge Management< 12.7

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-34203?

CVE-2023-34203 is a vulnerability with a CVSS score of 8.8 (HIGH). In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role memb...

How severe is CVE-2023-34203?

CVE-2023-34203 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-34203?

Check the references section above for vendor advisories and patch information. Affected products include: Progress Openedge, Progress Openedge Explorer, Progress Openedge Management.