Vulnerability Description
In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x before 12.2.12, and 12.3.x through 12.6.x before 12.7.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Progress | Openedge | < 11.7.16 |
| Progress | Openedge Explorer | < 12.7 |
| Progress | Openedge Management | < 12.7 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2023-34203?
CVE-2023-34203 is a vulnerability with a CVSS score of 8.8 (HIGH). In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role memb...
How severe is CVE-2023-34203?
CVE-2023-34203 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-34203?
Check the references section above for vendor advisories and patch information. Affected products include: Progress Openedge, Progress Openedge Explorer, Progress Openedge Management.