CVE-2025-7388 - CVE House
Back to Database
Status published High CVE-2025-7388

Authenticated Command Injection via configuration parameter manipulation in exposed RMI interface

Vulnerability Description

It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and execute OS commands under the delegated authority of the AdminServer process.  An RMI interface permitted manipulation of a configuration property with inadequate input validation leading to OS command injection.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-7388

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Progress Software Corporation

View all reports →

Affected Software

OpenEdge
Vulnerable Versions:
OpenEdge 12.2.0, OpenEdge 12.8.0

Timeline

Official Publish: September 4th, 2025
Last Modified: February 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

Weaknesses (CWE)