CVE Explorer
CVE-2025-7389
A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server
through the adopted authority of the AdminServer process itself. The delegated authority of the AdminServer could allow its users the ability to read arbitrary files on the host system through the misuse of the setFile() and openFile()
methods exposed through the RMI interface. Misuse was limited only by OS-level authority of the AdminServer's elevat
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"affected","modules":["OpenEdge AdminServer"],"platforms":["Windows","Linux","64 bit","32 bit"],"product":"OpenEdge","vendor":"Progress Software Corporation","versions":[{"lessThanOrEqual":"12.2.9","status":"affected","version":"OpenEdge 12.2.0","versionType":"custom"},{"lessThanOrEqual":"12.2.18","status":"affected","version":"OpenEdge 12.8.0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:74fc18b82c23af8d8795939e40d55c74843bff4a123949a9a26bba00db0be2ed · sha256:7e54ebe4886183d6… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.2,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:74fc18b82c23af8d8795939e40d55c74843bff4a123949a9a26bba00db0be2ed · sha256:7e54ebe4886183d6… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-552","description":"CWE-552","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:74fc18b82c23af8d8795939e40d55c74843bff4a123949a9a26bba00db0be2ed · sha256:7e54ebe4886183d6… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://community.progress.com/s/article/Important-Arbitrary-File-Ready-Security-Update-for-OpenEdge-AdminServer"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:74fc18b82c23af8d8795939e40d55c74843bff4a123949a9a26bba00db0be2ed · sha256:7e54ebe4886183d6… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.