iTnews Asia
  • Home
  • News
  • Software

Progress Software patches critical OpenEdge vulnerability

Progress Software patches critical OpenEdge vulnerability

Attack via malicious file uploads.

By Richard Chirgwin on Jan 22, 2024 11:52AM

Progress Software has disclosed a critical vulnerability in several versions of its Progress Application Server in OpenEdge (PASOE) software.

According to an advisory, CVE-2023-40051 affects OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0.

“An attacker can formulate a request for a web transport that allows unintended file uploads to a server directory path on the system running PASOE," the advisory states.

“If the upload contains a payload that can further exploit the server or its network, the launch of a larger scale attack may be possible.”

Progress Software explained that the web transport supports file uploads “across all web handlers” via built-in handlers.

“The expected behaviour is that file upload is disabled by default since the value for the ‘fileUploadDirectory’ property in the openedge.properties file is blank," the company said.

The problem is, the default setting gives the user account that launched the PASOE instance “access to all directories”, and if the directories have write permission, the system is subject to malicious file upload on Linux or on the root drive under Windows.

Users that can’t patch immediately are advised a temporary mitigation is available by setting the “fileUploadDirectory” configuration property to a non-existent directory.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
openedge progress software software

Related Articles

  • Philippines’ Security Bank modernises eKYC for secure customer onboarding
  • The outlook for software development in 2025
  • Malaysia launches national AI office for policy, regulation
  • Semyung University transforms IT infrastructure with NetApp
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Philippines’ Jollibee to modernise applications used by 3,200 stores

Philippines’ Jollibee to modernise applications used by 3,200 stores

The outlook for software development in 2025

The outlook for software development in 2025

Digital is the way forward for Cargill, says regional IT head

Digital is the way forward for Cargill, says regional IT head

Nanyang Technological University revamps digital presence

Nanyang Technological University revamps digital presence

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.