It was possible to perform Remote Command Execution (RCE) via Java
RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and
execute OS commands under the delegated authority of the AdminServer process. An RMI interface permitted manipulation of a configuration
property with inadequate input validation leading to OS command injection.
References
Configurations
No configuration.
History
04 Sep 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-04 13:15
Updated : 2025-09-04 15:35
NVD link : CVE-2025-7388
Mitre link : CVE-2025-7388
CVE.ORG link : CVE-2025-7388
JSON object : View
Products Affected
No product.
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')