This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE. If the upload contains a payload that can further exploit the server or its network, the launch of a larger scale attack may be possible.
An attacker crafts a specially prepared request to the WEB transport handled by PASOE, which enables uncontrolled file upload to any directory path on the server. The file validation mechanism is insufficient (CWE-434: Unrestricted Upload of File with Dangerous Type), allowing placement of a file containing a malicious payload on the server. If the uploaded file can then be executed or processed by the server or other network components, it is possible to escalate the attack.
An attacker can upload a malicious file to the server, which may lead to further system or network compromise, including potential code execution, data integrity violation, and escalation to an attack on broader infrastructure.
Progress Application Server for OpenEdge should be updated to version 11.7.18 or later (for the 11.7 branch), 12.2.13 or later (for the 12.2 branch), or 12.8.0 or later (for innovation releases). Detailed instructions are available in the vendor's official security advisory at the address indicated in the references.
Progress Application Server (PAS) for OpenEdge in versions 11.7 before 11.7.18, 12.2 before 12.2.13, and innovation releases before 12.8.0
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:LProgress Openedge
APPProgress11.7 – 11.7.18 (excl.)12.2 – 12.2.13 (excl.)Progress Openedge Innovation
APPProgress< 12.8.0
Related vulnerabilities
Authentication bypass w Progress OpenEdge Authentication Gateway i AdminServer
RCE w Progress OpenEdge — niezabezpieczony Java RMI class loader na porcie 20931
Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized cod...
Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are use...
An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OE...