CVE-2023-40051
Dashboard / Vulnerabilities / CVE-2023-40051
CVE-2023-40051
Summary:
Details: This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE. If the upload contains a payload that can further exploit the server or its network, the launch of a larger scale attack may be possible.
References: https://www.progress.com/openedge, , https://community.progress.com/s/article/Important-Progress-OpenEdge-Critical-Alert-for-Progress-Application-Server-in-OpenEdge-PASOE-Arbitrary-File-Upload-Vulnerability-in-WEB-Transport
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
