CVE-2015-9245
Status: ModifiedCritical (9.8)—
Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 9.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.86%
- Percentile among all scored CVEs: 78
- Score date: 10/1/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-284
References
Raw JSON (NVD)
Show
{
"id": "CVE-2015-9245",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2017-10-31T07:29:00.190",
"references": [
{
"url": "https://knowledgebase.progress.com/articles/Article/How-to-prevent-Java-RMI-class-loader-exploit-with-AdminServer",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://knowledgebase.progress.com/articles/Article/How-to-prevent-Java-RMI-class-loader-exploit-with-AdminServer",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931."
},
{
"lang": "es",
"value": "Una configuración por defecto insegura en Progress Software OpenEdge, en sus versiones 10.2x y 11.x permite que atacantes remotos no autenticados especifiquen URL arbitrarios desde los que cargar y ejecutar clases Java maliciosas mediante el puerto 20931."
}
],
"lastModified": "2026-06-17T00:36:07.617",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:progress:openedge:10.2a:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "852A1525-7E6D-4A38-96F7-F3C18C4ADF63"
},
{
"criteria": "cpe:2.3:a:progress:openedge:10.2b:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4944214F-208F-4BC1-B346-F33E9A080D6C"
},
{
"criteria": "cpe:2.3:a:progress:openedge:10.2b07:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5980BF8F-C281-437B-9200-DCBA73CA32D8"
},
{
"criteria": "cpe:2.3:a:progress:openedge:10.2b08:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2853DCD2-B5C1-4902-A260-53E8E18FF10F"
},
{
"criteria": "cpe:2.3:a:progress:openedge:11.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91509519-1BDB-41AE-B1D3-32471EC7C2EA"
},
{
"criteria": "cpe:2.3:a:progress:openedge:11.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C06FEF66-E682-44FF-83FF-FBE892FEBA70"
},
{
"criteria": "cpe:2.3:a:progress:openedge:11.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3D6B0D87-886D-4471-95F5-A2A53F5A127F"
},
{
"criteria": "cpe:2.3:a:progress:openedge:11.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "78CB871F-677C-4B32-BAA9-60A4F91E7FD4"
},
{
"criteria": "cpe:2.3:a:progress:openedge:11.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7D7E32C7-E7BC-4D48-B91D-031650A94016"
},
{
"criteria": "cpe:2.3:a:progress:openedge:11.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0A87C26-27E7-4669-B033-902023853EBE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}