{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-21T13:18:04.127","vulnerabilities":[{"cve":{"id":"CVE-2025-7388","sourceIdentifier":"security@progress.com","published":"2025-09-04T13:15:45.533","lastModified":"2026-06-17T10:04:49.600","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"It was possible to perform Remote Command Execution (RCE) via Java\nRMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and\nexecute OS commands under the delegated authority of the AdminServer process.  An RMI interface permitted manipulation of a configuration\nproperty with inadequate input validation leading to OS command injection."}],"affected":[{"source":"security@progress.com","affectedData":[{"vendor":"Progress Software Corporation","product":"OpenEdge","defaultStatus":"unaffected","modules":["OpenEdge AdminServer"],"platforms":["Windows","Linux","64 bit","32 bit"],"versions":[{"version":"OpenEdge 12.2.0","lessThan":"12.2.18","versionType":"custom","status":"affected"},{"version":"OpenEdge 12.8.0","lessThan":"12.8.8","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@progress.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-05T03:55:49.088535Z","id":"CVE-2025-7388","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@progress.com","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]}],"references":[{"url":"https://community.progress.com/s/article/Important-RCE-Security-Update-for-OpenEdge-AdminServer","source":"security@progress.com"}]}}]}