CVE-2024-7654: Unauthenticated Content Injection in OpenEdge Management web interface via ActiveMQ discovery service
An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated. Unauthorized access to the discovery service's UDP port allowed content injection into parts of the OEM web interface making it possible for other types of attack that could spoof or deceive web interface users. Unauthorized use of the OEE/OEM discovery service was remediated by deactivating the discovery service by default.
Affected Software
Remediation
Information
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7654?
CVE-2024-7654 has a high severity rating due to the potential for unauthorized access and content injection.
How do I fix CVE-2024-7654?
To fix CVE-2024-7654, disable the auto-discovery feature in OpenEdge Management and ensure that the UDP port for the ActiveMQ Discovery service is not accessible.
What software versions are affected by CVE-2024-7654?
CVE-2024-7654 affects Progress OpenEdge versions up to 11.7.19 and versions 12.2.0 to 12.2.14, as well as certain versions from 12.8.0 to below 12.8.3.
What types of attacks are possible with CVE-2024-7654?
Exploitation of CVE-2024-7654 could allow for unauthorized content injection into the OpenEdge Management web interface.
Is CVE-2024-7654 related to any specific feature in OpenEdge Management?
CVE-2024-7654 is specifically related to the OEE/OEM auto-discovery feature that exposes the ActiveMQ Discovery service.