CVE-2015-9245
Estado: ModificadaCrítica (9.8)—
Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.86%
- Percentil entre todas las CVEs puntuadas: 78
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-284
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2015-9245",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2017-10-31T07:29:00.190",
"references": [
{
"url": "https://knowledgebase.progress.com/articles/Article/How-to-prevent-Java-RMI-class-loader-exploit-with-AdminServer",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://knowledgebase.progress.com/articles/Article/How-to-prevent-Java-RMI-class-loader-exploit-with-AdminServer",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931."
},
{
"lang": "es",
"value": "Una configuración por defecto insegura en Progress Software OpenEdge, en sus versiones 10.2x y 11.x permite que atacantes remotos no autenticados especifiquen URL arbitrarios desde los que cargar y ejecutar clases Java maliciosas mediante el puerto 20931."
}
],
"lastModified": "2026-06-17T00:36:07.617",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:progress:openedge:10.2a:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "852A1525-7E6D-4A38-96F7-F3C18C4ADF63"
},
{
"criteria": "cpe:2.3:a:progress:openedge:10.2b:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4944214F-208F-4BC1-B346-F33E9A080D6C"
},
{
"criteria": "cpe:2.3:a:progress:openedge:10.2b07:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5980BF8F-C281-437B-9200-DCBA73CA32D8"
},
{
"criteria": "cpe:2.3:a:progress:openedge:10.2b08:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2853DCD2-B5C1-4902-A260-53E8E18FF10F"
},
{
"criteria": "cpe:2.3:a:progress:openedge:11.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91509519-1BDB-41AE-B1D3-32471EC7C2EA"
},
{
"criteria": "cpe:2.3:a:progress:openedge:11.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C06FEF66-E682-44FF-83FF-FBE892FEBA70"
},
{
"criteria": "cpe:2.3:a:progress:openedge:11.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3D6B0D87-886D-4471-95F5-A2A53F5A127F"
},
{
"criteria": "cpe:2.3:a:progress:openedge:11.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "78CB871F-677C-4B32-BAA9-60A4F91E7FD4"
},
{
"criteria": "cpe:2.3:a:progress:openedge:11.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7D7E32C7-E7BC-4D48-B91D-031650A94016"
},
{
"criteria": "cpe:2.3:a:progress:openedge:11.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0A87C26-27E7-4669-B033-902023853EBE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}