DNA View

High Severity Vulnerability

This vulnerability has been rated as High severity. Immediate action is recommended.

CVE-2024-7654

High
Low Medium High Critical
8.3
CVSS Score
Published: Sep 03, 2024
Last Modified: Sep 05, 2024

Vulnerability Description

An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated.  Unauthorized access to the discovery service's UDP port allowed content injection into parts of the OEM web interface making it possible for other types of attack that could spoof or deceive web interface users.   Unauthorized use of the OEE/OEM discovery service was remediated by deactivating the discovery service by default.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
N
Attack Complexity
H
Privileges Required
N
User Interaction
R
Scope
C
Confidentiality
H
Integrity
H
Availability
H

Known Affected Software

32 configuration(s) from 1 vendor(s)

openedge
Version:
12.2.5
CPE:
cpe:2.3:a:progress:openedge:12.2.5:*:*:*:lts:*:*:*
openedge
Version:
11.7.18
CPE:
cpe:2.3:a:progress:openedge:11.7.18:*:*:*:lts:*:*:*
openedge
Version:
12.2.6
CPE:
cpe:2.3:a:progress:openedge:12.2.6:*:*:*:lts:*:*:*
openedge
Version:
12.2.7
CPE:
cpe:2.3:a:progress:openedge:12.2.7:*:*:*:lts:*:*:*
openedge
Version:
12.2.10
CPE:
cpe:2.3:a:progress:openedge:12.2.10:*:*:*:lts:*:*:*
openedge
Version:
12.8.1
CPE:
cpe:2.3:a:progress:openedge:12.8.1:*:*:*:lts:*:*:*
openedge
Version:
12.2.3
CPE:
cpe:2.3:a:progress:openedge:12.2.3:*:*:*:lts:*:*:*
openedge
Version:
11.4
CPE:
cpe:2.3:a:progress:openedge:11.4:*:*:*:*:*:*:*
openedge
Version:
11.0
CPE:
cpe:2.3:a:progress:openedge:11.0:*:*:*:*:*:*:*
openedge
Version:
12.2.9
CPE:
cpe:2.3:a:progress:openedge:12.2.9:*:*:*:lts:*:*:*
openedge
Version:
10.2b
CPE:
cpe:2.3:a:progress:openedge:10.2b:*:*:*:*:*:*:*
openedge
Version:
10.2a
CPE:
cpe:2.3:a:progress:openedge:10.2a:*:*:*:*:*:*:*
openedge
Version:
12.2
CPE:
cpe:2.3:a:progress:openedge:12.2:*:*:*:lts:*:*:*
openedge
Version:
11.7
CPE:
cpe:2.3:a:progress:openedge:11.7:*:*:*:*:*:*:*
openedge
Version:
10.2b07
CPE:
cpe:2.3:a:progress:openedge:10.2b07:*:*:*:*:*:*:*
openedge
Version:
11.2
CPE:
cpe:2.3:a:progress:openedge:11.2:*:*:*:*:*:*:*
openedge
Version:
11.7.16
CPE:
cpe:2.3:a:progress:openedge:11.7.16:*:*:*:lts:*:*:*
openedge
Version:
10.1b
CPE:
cpe:2.3:a:progress:openedge:10.1b:*:*:*:*:*:*:*
openedge
Version:
11.5
CPE:
cpe:2.3:a:progress:openedge:11.5:*:*:*:*:*:*:*
openedge
Version:
12.2.12
CPE:
cpe:2.3:a:progress:openedge:12.2.12:*:*:*:lts:*:*:*
openedge
Version:
12.2.14
CPE:
cpe:2.3:a:progress:openedge:12.2.14:*:*:*:lts:*:*:*
openedge
Version:
12.2.11
CPE:
cpe:2.3:a:progress:openedge:12.2.11:*:*:*:lts:*:*:*
openedge
Version:
11.1
CPE:
cpe:2.3:a:progress:openedge:11.1:*:*:*:*:*:*:*
openedge
Version:
10.2b08
CPE:
cpe:2.3:a:progress:openedge:10.2b08:*:*:*:*:*:*:*
openedge
Version:
11.7.19
CPE:
cpe:2.3:a:progress:openedge:11.7.19:*:*:*:lts:*:*:*
openedge
Version:
12.8
CPE:
cpe:2.3:a:progress:openedge:12.8:*:*:*:lts:*:*:*
openedge
Version:
11.3
CPE:
cpe:2.3:a:progress:openedge:11.3:*:*:*:*:*:*:*
openedge
Version:
12.2.13
CPE:
cpe:2.3:a:progress:openedge:12.2.13:*:*:*:lts:*:*:*
openedge
Version:
12.2.4
CPE:
cpe:2.3:a:progress:openedge:12.2.4:*:*:*:lts:*:*:*
openedge
Version:
12.2.8
CPE:
cpe:2.3:a:progress:openedge:12.2.8:*:*:*:lts:*:*:*
openedge
Version:
12.8.2
CPE:
cpe:2.3:a:progress:openedge:12.8.2:*:*:*:lts:*:*:*
openedge
Version:
10.1a
CPE:
cpe:2.3:a:progress:openedge:10.1a:*:*:*:*:*:*:*
This vulnerability affects 32 software configuration(s). Ensure you patch all affected systems.

Severity Details

8.3
out of 10.0
High

Weakness Type (CWE)

CWE-79 Top 25 #1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Exploit Likelihood
High
Typical Severity
Medium
OWASP Top 10
A03:2021-Injection
Abstraction Level
Base

Key Information

Published Date
September 03, 2024

Related News Articles

Latest news and updates about CVE-2024-7654