The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications. OECH1 encodings should be considered exploitable and immediately replaced by any other supported prefix encoding, all of which are based on symmetric encryption.
OECH1 encoding is intended for obfuscating values within the OpenEdge platform, however it is not based on strong cryptographic mechanisms. Unlike other supported prefix-based encoding methods, which are based on symmetric encryption, OECH1 does not provide adequate protection. An attacker with access to encoded values can restore them to plain text without knowledge of the cryptographic key.
An attacker can recover protected values — such as passwords or secret configuration data — stored using OECH1 encoding, which could lead to unauthorized access to enterprise systems and resources.
All existing values encoded using OECH1 must be immediately replaced with other supported encoding methods with prefixes based on symmetric encryption. Detailed migration instructions are available at the address indicated in the manufacturer's references (community.progress.com).
All implementations of the Progress OpenEdge platform using OECH1 encoding to store passwords or secret values; detailed information about versions is available in the manufacturer's references.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:D/RE:M/U:Red