CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. It may be remotely exploitable.
CVE
CVE-2023-34203
Severity
HIGH
CVSS
8.8
EPSS
1.06%
Original NVD Description
In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x before 12.2.12, and 12.3.x through 12.6.x before 12.7.
Related CVEs
Other vulnerabilities affecting the same vendor(s)