CVE-2024-7345: Direct local client connections to MS Agents can bypass authentication
Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents on supported OpenEdge LTS platforms up to OpenEdge LTS 11.7.18 and LTS 12.2.13 on all supported release platforms
Affected Software
Remediation
Information
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7345?
CVE-2024-7345 has a severity rating that indicates a significant risk of unauthorized code injection due to bypassed security checks.
How do I fix CVE-2024-7345?
To fix CVE-2024-7345, upgrade to OpenEdge LTS version 11.7.19 or higher, or LTS 12.2.14 or higher.
Which versions of OpenEdge are affected by CVE-2024-7345?
CVE-2024-7345 affects OpenEdge LTS versions up to 11.7.18 and versions between 12.0 and 12.2.13.
Can CVE-2024-7345 allow remote attacks?
CVE-2024-7345 primarily allows local attackers to bypass security controls, hence it does not facilitate remote attacks.
What types of attacks can CVE-2024-7345 lead to?
CVE-2024-7345 can lead to unauthorized code injection into Multi-Session Agents, posing a risk to application integrity.