Back

HIGH

Unauthenticated Content Injection in OpenEdge Management web interface via ActiveMQ discovery service

Published Sep 3, 2024

Description

An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated.  Unauthorized access to the discovery service's UDP port allowed content injection into parts of the OEM web interface making it possible for other types of attack that could spoof or deceive web interface users.   Unauthorized use of the OEE/OEM discovery service was remediated by deactivating the discovery service by default.

Affected products

Remediation

Vendor solution

Use the 12.8.3 or above LTS release where the vulnerability does not exist

Use the 12.2 LTS release at the 12.2.15 Update level or above

Use the 11.7 LTS release at the 11.7.20 Update level or above

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ProgressSoftware
Published Sep 3, 2024
Updated Sep 3, 2024
Reserved Aug 9, 2024
CISA Vulnrichment
Updated Sep 3, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ProgressSoftware
Published Sep 3, 2024
Updated Sep 3, 2024
Exploited since n/a
EUVD-2024-48539