CVE-2024-1403

In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified.  The vulnerability is a bypass to authentication based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication.  
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:openedge:*:*:*:*:lts:*:*:*
cpe:2.3:a:progress:openedge:*:*:*:*:lts:*:*:*
cpe:2.3:a:progress:openedge:*:*:*:*:lts:*:*:*

History

11 Feb 2025, 17:40

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Progress
Progress openedge
CPE cpe:2.3:a:progress:openedge:*:*:*:*:lts:*:*:*
References () https://community.progress.com/s/article/Important-Critical-Alert-for-OpenEdge-Authentication-Gateway-and-AdminServer - () https://community.progress.com/s/article/Important-Critical-Alert-for-OpenEdge-Authentication-Gateway-and-AdminServer - Vendor Advisory
References () https://www.progress.com/openedge - () https://www.progress.com/openedge - Product

21 Nov 2024, 08:50

Type Values Removed Values Added
References () https://community.progress.com/s/article/Important-Critical-Alert-for-OpenEdge-Authentication-Gateway-and-AdminServer - () https://community.progress.com/s/article/Important-Critical-Alert-for-OpenEdge-Authentication-Gateway-and-AdminServer -
References () https://www.progress.com/openedge - () https://www.progress.com/openedge -

28 Feb 2024, 14:07

Type Values Removed Values Added
Summary
  • (es) En OpenEdge Authentication Gateway y AdminServer anteriores a 11.7.19, 12.2.14, 12.8.1 en todas las plataformas compatibles con el producto OpenEdge, se identificó una vulnerabilidad de omisión de autenticación. La vulnerabilidad es una omisión de la autenticación basada en una falla al manejar adecuadamente el nombre de usuario y la contraseña. Cierto contenido inesperado que se pasa a las credenciales puede provocar un acceso no autorizado sin la autenticación adecuada.

27 Feb 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-27 16:15

Updated : 2025-02-11 17:40


NVD link : CVE-2024-1403

Mitre link : CVE-2024-1403

CVE.ORG link : CVE-2024-1403


JSON object : View

Products Affected

progress

  • openedge
CWE
CWE-305

Authentication Bypass by Primary Weakness

NVD-CWE-noinfo