CVE-2025-7388

It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and execute OS commands under the delegated authority of the AdminServer process.  An RMI interface permitted manipulation of a configuration property with inadequate input validation leading to OS command injection.
Configurations

No configuration.

History

04 Sep 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-04 13:15

Updated : 2025-09-04 15:35


NVD link : CVE-2025-7388

Mitre link : CVE-2025-7388

CVE.ORG link : CVE-2025-7388


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')