Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-7389— Unauthorized Arbitrary File Read via RMI in AdminServer Interface

Quick assessment

Affected
Progress Software Corporation OpenEdge
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Progress OpenEdge是美国Progress公司的一个企业级应用开发与数据库管理平台。 Progress OpenEdge存在安全漏洞,该漏洞源于AdminServer组件授权不当,可能导致认证用户通过RMI接口滥用setFile和openFile方法读取主机系统上的任意文件。

AI Predicted 8.1 Difficulty: Moderate EPSS 0.33% · P23
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-7389

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unauthorized Arbitrary File Read via RMI in AdminServer Interface
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server through the adopted authority of the AdminServer process itself.  The delegated authority of the AdminServer could allow its users the ability to read arbitrary files on the host system through the misuse of the setFile() and openFile() methods exposed through the RMI interface.  Misuse was limited only by OS-level authority of the AdminServer's elevated privileges granted and the user's access to these methods enabled through RMI.  The exploitable methods have been removed thus eliminating their access through RMI or downstream of the RMI registry.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对外部实体的文件或目录可访问
Source: CVE Program / CVE List V5
Vulnerability Title
Progress OpenEdge 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Progress OpenEdge是美国Progress公司的一个企业级应用开发与数据库管理平台。 Progress OpenEdge存在安全漏洞,该漏洞源于AdminServer组件授权不当,可能导致认证用户通过RMI接口滥用setFile和openFile方法读取主机系统上的任意文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Progress Software Corporation OpenEdge OpenEdge 12.2.0 ~ 12.2.9 -

II. Public POCs for CVE-2025-7389

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-7389

请登录查看更多情报信息。

Vendor Pages for CVE-2025-7389 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2025-7389

No comments yet


Leave a comment