Vulnerabilities (CVE)

Filtered by vendor Progress Subscribe
Filtered by product Connection Manager For Objectscale
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-3517 1 Progress 3 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster 2026-05-01 N/A 8.4 HIGH
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command
CVE-2026-3518 1 Progress 3 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster 2026-05-01 N/A 8.4 HIGH
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command
CVE-2026-3519 1 Progress 3 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster 2026-05-01 N/A 8.4 HIGH
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command
CVE-2026-4048 1 Progress 3 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster 2026-05-01 N/A 8.4 HIGH
OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.
CVE-2025-13444 1 Progress 5 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster and 2 more 2026-02-13 N/A 8.4 HIGH
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters