CVE-2024-1403: Progress Openedge
Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.
In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified. The vulnerability is a bypass to authentication based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication.
Affected products
- Progress Openedge: before 11.7.19 (fixed in 11.7.19); from 11.8, before 12.2.14 (fixed in 12.2.14); from 12.3, before 12.8.1 (fixed in 12.8.1)
Published 2024-02-27. Last modified 2026-06-17.