Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-40051

Опубликовано: 18 янв. 2024
Источник: nvd
CVSS3: 9.1
CVSS3: 9.9
EPSS Низкий

Описание

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE. If the upload contains a payload that can further exploit the server or its network, the launch of a larger scale attack may be possible.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:progress:openedge:*:*:*:*:*:*:*:*
Версия от 11.7 (включая) до 11.7.18 (исключая)
cpe:2.3:a:progress:openedge:*:*:*:*:*:*:*:*
Версия от 12.2 (включая) до 12.2.13 (исключая)
Конфигурация 2
cpe:2.3:a:progress:openedge_innovation:*:*:*:*:*:*:*:*
Версия до 12.8.0 (исключая)

EPSS

Процентиль: 6%
0.00024
Низкий

9.1 Critical

CVSS3

9.9 Critical

CVSS3

Дефекты

CWE-434
CWE-434

Связанные уязвимости

CVSS3: 9.1
github
около 2 лет назад

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE. If the upload contains a payload that can further exploit the server or its network, the launch of a larger scale attack may be possible.

EPSS

Процентиль: 6%
0.00024
Низкий

9.1 Critical

CVSS3

9.9 Critical

CVSS3

Дефекты

CWE-434
CWE-434