« Back to list

CVE-2015-9245

Status: ModifiedCritical (9.8)—

Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2015-9245",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-10-31T07:29:00.190",
  "references": [
    {
      "url": "https://knowledgebase.progress.com/articles/Article/How-to-prevent-Java-RMI-class-loader-exploit-with-AdminServer",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://knowledgebase.progress.com/articles/Article/How-to-prevent-Java-RMI-class-loader-exploit-with-AdminServer",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931."
    },
    {
      "lang": "es",
      "value": "Una configuración por defecto insegura en Progress Software OpenEdge, en sus versiones 10.2x y 11.x permite que atacantes remotos no autenticados especifiquen URL arbitrarios desde los que cargar y ejecutar clases Java maliciosas mediante el puerto 20931."
    }
  ],
  "lastModified": "2026-06-17T00:36:07.617",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:progress:openedge:10.2a:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "852A1525-7E6D-4A38-96F7-F3C18C4ADF63"
            },
            {
              "criteria": "cpe:2.3:a:progress:openedge:10.2b:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4944214F-208F-4BC1-B346-F33E9A080D6C"
            },
            {
              "criteria": "cpe:2.3:a:progress:openedge:10.2b07:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5980BF8F-C281-437B-9200-DCBA73CA32D8"
            },
            {
              "criteria": "cpe:2.3:a:progress:openedge:10.2b08:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2853DCD2-B5C1-4902-A260-53E8E18FF10F"
            },
            {
              "criteria": "cpe:2.3:a:progress:openedge:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91509519-1BDB-41AE-B1D3-32471EC7C2EA"
            },
            {
              "criteria": "cpe:2.3:a:progress:openedge:11.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C06FEF66-E682-44FF-83FF-FBE892FEBA70"
            },
            {
              "criteria": "cpe:2.3:a:progress:openedge:11.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D6B0D87-886D-4471-95F5-A2A53F5A127F"
            },
            {
              "criteria": "cpe:2.3:a:progress:openedge:11.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78CB871F-677C-4B32-BAA9-60A4F91E7FD4"
            },
            {
              "criteria": "cpe:2.3:a:progress:openedge:11.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D7E32C7-E7BC-4D48-B91D-031650A94016"
            },
            {
              "criteria": "cpe:2.3:a:progress:openedge:11.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0A87C26-27E7-4669-B033-902023853EBE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}