CVE-2025-7389Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server through the adopted authority of the AdminServer process itself.  The delegated authority of the AdminServer could allow its users the ability to read arbitrary files on the host system through the misuse of the setFile() and openFile() methods exposed through the RMI interface.  Misuse was limited only by OS-level authority of the AdminServer's elevated privileges granted and the user's access to these methods enabled through RMI.  The exploitable methods have been removed thus eliminating their access through RMI or downstream of the RMI registry.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-552

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-19); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1Technical Details · 2026-04-19: 104-1904-21
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Progress ❗ CVE-2025-8095 ❗ CVE-2025-7389 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-progress-software/ https://t.co/AhhP1Y0iDi

    Post summary

    This message announces the existence of two Vulnerability CVEs affecting Progress products, linking to an advisory, with no evidence of PoC, exploit, active exploitation, patches, or technical details.

    00000321
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-7389 A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server through the adopted aut… https://www.cve.org/CVERecord?id=CVE-2025-7389

    Post summary

    CVE-2025-7389 affects OpenEdge's AdminServer, allowing authenticated users to gain OS-level access; no exploit, patch, or PoC details are provided.

    00000136
    57.2K followersView on X

Explore more