Back to Database
Status published
High
CVE-2024-7345
Direct local client connections to MS Agents can bypass authentication
Vulnerability Description
Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents on supported OpenEdge LTS platforms up to OpenEdge LTS 11.7.18 and LTS 12.2.13 on all supported release platforms
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-7345
Credits & Attribution
No credits recorded in the NVD database.
More from Progress
View All →CVE-2025-2324
A MOVEit Transfer user configured as a Shared Account can gain unintended List permissions on a folder
Medium
5.9
CVE-2025-1758
Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer...
Medium
4.3
CVE-2025-13147
External Service Interaction (DNS)
Medium
5.3
CVE-2025-11235
MOVEit Transfer REST API does not require current password in order to initiate the password change process
Low
3.7
CVE-2025-10932
AS2 module allows uncontrolled file uploads
High
8.2
Affected Vendor
Progress
View all reports →Affected Software
OpenEdge
Vulnerable Versions:
11.7.0, 12.2.0, 12.8.0
Timeline
Official Publish:
September 3rd, 2024
Last Modified:
September 3rd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H