← Back to browse · API

CVE-2024-1403

Severity
CRITICAL
CVSS
10.0
EPSS
0.033
Risk score
41.16
CISA KEV
No
PoC
No
Published
2024-02-27
Modified
2024-08-12
First seen
2026-08-07
Aliases
EUVD-2024-17158, GHSA-M24W-WG7M-X27H
Products
Progress Software Corporation:OpenEdge, Progress Software Corporation:OpenEdge 11.7.0 <11.7.19, Progress Software Corporation:OpenEdge 12.2.0 <12.2.14, Progress Software Corporation:OpenEdge 12.8.0 <12.8.1
Sources
euvd EUVD-2024-17158

Description

In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified.  The vulnerability is a bypass to authentication based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication.

References