PoC Index

CVE-2015-9245

CRITICAL 9.8EPSS 1.9%

Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.86% chance of exploitation in the next 30 days, 78th percentile
Published
2017-10-31
Updated
2024-08-06

Proof-of-concept exploits (1)

References

Related