CVE-2023-40051
Last modified
CVE-2023-40051 is a critical-severity vulnerability rated 9.9/10 on the CVSS scale. This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE. If the upload contains a payload that can further exploit the server or its network, the launch of a larger scale attack may be possible. . EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE. If the upload contains a payload that can further exploit the server or its network, the launch of a larger scale attack may be possible.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Progress | Openedge | >= 11.7, < 11.7.18 |
| Progress | Openedge | >= 12.2, < 12.2.13 |
| Progress | Openedge Innovation | < 12.8.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-40051?
How severe is CVE-2023-40051?
How do I fix CVE-2023-40051?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-40046 In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a S…7.2
- CVE-2023-40047 In WS_FTP Server version prior to 8.8.2, a stored cross-s…4.8
- CVE-2023-40048 In WS_FTP Server version prior to 8.8.2, the WS_FTP Ser…6.5
- CVE-2023-40049 In WS_FTP Server version prior to 8.8.2, an unauthentic…5.3
- CVE-2023-4005Insufficient Session Expiration in GitHub repository fossbil…9.8
- CVE-2023-40050Upload profile either through API or user interface in Chef …8.8
- CVE-2023-40052 This issue affects Progress Application Server (PAS) for …7.5
- CVE-2023-40053A vulnerability has been identified within Serv-U 15.4 that …5
- CVE-2023-40054The Network Configuration Manager was susceptible to a Direc…8.8
- CVE-2023-40055The Network Configuration Manager was susceptible to a Direc…8.8
- CVE-2023-40056 SQL Injection Remote Code Vulnerability was foun…8.8
- CVE-2023-40057The SolarWinds Access Rights Manager was found to be suscept…9
Are you affected by CVE-2023-40051?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
