CVE-2025-7389
A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server through the adopted authority of the AdminServer process itself. The delegated authority of the AdminServer could allow its users the ability to read arbitrary files on the host system through the misuse of the setFile() and openFile() methods exposed through the RMI interface. Misuse was limited only by OS-level authority of the AdminServer's elevated privileges granted and the user's access to these methods enabled through RMI. The exploitable methods have been removed thus eliminating their access through RMI or downstream of the RMI registry.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 23
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement85 % - Impacto principal
T1005Data from Local Systemcollection90 % - Impacto secundario
T1021.003Distributed Component Object Modellateral movement75 %
Vulnerabilidad en AdminServer (RMI) que requiere autenticación (PR:H) en red. Impacto: lectura de archivos arbitrarios (T1005) con privilegios elevados del proceso; acceso remoto a través de RMI/interfaces Java (T1021.003).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-552
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-7389",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-7389",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-04-14T14:01:57.322738Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "security@progress.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.2,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "HIGH",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "security@progress.com",
"affectedData": [
{
"vendor": "Progress Software Corporation",
"modules": [
"OpenEdge AdminServer"
],
"product": "OpenEdge",
"versions": [
{
"status": "affected",
"version": "OpenEdge 12.2.0",
"versionType": "custom",
"lessThanOrEqual": "12.2.9"
},
{
"status": "affected",
"version": "OpenEdge 12.8.0",
"versionType": "custom",
"lessThanOrEqual": "12.2.18"
}
],
"platforms": [
"Windows",
"Linux",
"64 bit",
"32 bit"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-04-14T14:16:10.263",
"references": [
{
"url": "https://community.progress.com/s/article/Important-Arbitrary-File-Ready-Security-Update-for-OpenEdge-AdminServer",
"source": "security@progress.com"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "security@progress.com",
"description": [
{
"lang": "en",
"value": "CWE-552"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server\nthrough the adopted authority of the AdminServer process itself. The delegated authority of the AdminServer could allow its users the ability to read arbitrary files on the host system through the misuse of the setFile() and openFile()\n methods exposed through the RMI interface. Misuse was limited only by OS-level authority of the AdminServer's elevated \nprivileges granted and the user's access to these methods enabled through RMI. The exploitable methods have been removed thus eliminating their access through RMI or downstream of the RMI registry."
},
{
"lang": "es",
"value": "Una vulnerabilidad en el componente AdminServer de OpenEdge en todas las plataformas compatibles otorga a sus usuarios autenticados acceso a nivel de SO al servidor a través de la autoridad adoptada del propio proceso AdminServer. La autoridad delegada del AdminServer podría permitir a sus usuarios la capacidad de leer archivos arbitrarios en el sistema host a través del uso indebido de los métodos setFile() y openFile() expuestos a través de la interfaz RMI. El uso indebido estaba limitado solo por la autoridad a nivel de SO de los privilegios elevados concedidos al AdminServer y el acceso del usuario a estos métodos habilitado a través de RMI. Los métodos explotables han sido eliminados, eliminando así su acceso a través de RMI o aguas abajo del registro RMI."
}
],
"lastModified": "2026-09-30T22:10:00.273",
"sourceIdentifier": "security@progress.com"
}