CVE-2025-7388
Progress OpenEdge vulnerability analysis and mitigation

Overview

CVE-2025-7388 is a Remote Command Execution (RCE) vulnerability in the Progress Software OpenEdge AdminServer, exploitable via its Java RMI interface. Authenticated users with low privileges can inject and execute arbitrary OS commands under the delegated authority of the AdminServer process due to inadequate input validation on a configuration property. Affected versions include OpenEdge 12.2.0 through 12.2.17 (fixed in 12.2.18) and OpenEdge 12.8.0 through 12.8.7 (fixed in 12.8.8). The vulnerability was published on September 4, 2025, and carries a CVSS v3.1 base score of 8.4 (High) (Red Hat CVE, ENISA EUVD).

Technical details

The root cause is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — Command Injection). The OpenEdge AdminServer exposes a Java RMI interface that allows manipulation of a configuration property; because user-supplied input is not adequately sanitized before being passed to OS-level command execution, an authenticated attacker can inject shell metacharacters or command delimiters to execute arbitrary commands. Exploitation requires network access to the RMI interface and at least low-privilege authentication, but no user interaction. A technical write-up detailing the exploitation path was published by Core Security (Core Security Blog).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary OS commands with the privileges of the AdminServer process, resulting in high confidentiality and integrity impact and low availability impact. An attacker could exfiltrate sensitive data, manipulate system configurations, deploy backdoors, or use the compromised server as a pivot point for lateral movement within the network. The changed scope indicator in the CVSS vector reflects that the impact can extend beyond the AdminServer itself to other components on the host or network (Red Hat CVE, ENISA EUVD).

Exploitability

As of the time of publication, there is no confirmed public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.257%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the vulnerability was featured in security community roundups and trending CVE lists shortly after disclosure, indicating elevated researcher interest (Reddit CVEWatch, The Hacker News).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Progress OpenEdge AdminServer instances running vulnerable versions (12.2.0–12.2.17 or 12.8.0–12.8.7) using network scanning tools such as Nmap targeting common RMI ports (default 1099/TCP).
  2. Authentication: Obtain low-privilege credentials for the OpenEdge AdminServer. These may be default credentials, credentials obtained through phishing, or credentials reused from other systems.
  3. Connect via Java RMI: Use a Java RMI client to connect to the AdminServer's exposed RMI interface and enumerate available remote objects and methods.
  4. Identify vulnerable configuration property: Locate the configuration property exposed through the RMI interface that is susceptible to command injection due to insufficient input validation.
  5. Inject OS command payload: Set the vulnerable configuration property to a value containing OS command injection syntax (e.g., using shell metacharacters such as ;, &&, |, or backticks) embedding the desired command (e.g., a reverse shell or data exfiltration command).
  6. Trigger execution: Invoke the appropriate RMI method that processes the manipulated configuration property, causing the AdminServer to execute the injected OS command with its own process privileges.
  7. Establish persistence: Use the achieved command execution to deploy a web shell, create a backdoor user, or establish a persistent reverse shell for continued access (Core Security Blog).

Indicators of compromise

  • Network: Unexpected inbound connections to the OpenEdge AdminServer RMI port (default 1099/TCP) from unusual or external IP addresses; outbound connections from the AdminServer host to unknown external IPs or C2 infrastructure.
  • Logs: AdminServer logs showing configuration property modification requests with anomalous values containing shell metacharacters (;, |, &&, backticks); authentication events for low-privilege accounts followed immediately by configuration changes.
  • Process: Unusual child processes spawned by the OpenEdge AdminServer process (e.g., cmd.exe, powershell.exe, /bin/sh, /bin/bash, curl, wget, nc); processes running under the AdminServer service account performing unexpected actions.
  • File System: New or modified files in OpenEdge installation directories; unexpected scripts, executables, or scheduled tasks created by the AdminServer service account; presence of web shells or reverse shell binaries.

Mitigation and workarounds

Progress Software has released patched versions: OpenEdge 12.2.18 and OpenEdge 12.8.8, which address the inadequate input validation in the RMI interface (ENISA EUVD, Progress Community). Organizations unable to patch immediately should restrict network access to the AdminServer RMI port using firewalls or network segmentation, limiting exposure to only trusted administrative hosts. Additional interim measures include enforcing the principle of least privilege for AdminServer accounts, enabling detailed audit logging of administrative interface access, and monitoring for anomalous configuration changes.

Community reactions

The vulnerability received coverage from multiple security news outlets including CyberSecurityNews, SecurityOnline, and The Hacker News' weekly recap, indicating broad community awareness (CyberSecurityNews, SecurityOnline, The Hacker News). Core Security published a technical blog post detailing the exploitation path, titled "Completing the Circle: Path to CVE-2025-7388" (Core Security Blog). The CVE appeared in a Reddit CVEWatch trending list for the week of September 7, 2025, and was noted in the BornCity blog in the context of its impact on proALPHA ERP systems that use OpenEdge as a backend (BornCity).

Additional resources


SourceThis report was generated using AI

Related Progress OpenEdge vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-8095CRITICAL9.1
  • Progress OpenEdge logoProgress OpenEdge
  • cpe:2.3:a:progress:openedge
NoYesApr 14, 2026
CVE-2025-7388HIGH8.4
  • Progress OpenEdge logoProgress OpenEdge
  • cpe:2.3:a:progress:openedge
NoYesSep 04, 2025
CVE-2025-7389HIGH8.2
  • Progress OpenEdge logoProgress OpenEdge
  • cpe:2.3:a:progress:openedge
NoYesApr 14, 2026
CVE-2024-7654MEDIUM6.1
  • Progress OpenEdge logoProgress OpenEdge
  • cpe:2.3:a:progress:openedge
NoYesSep 03, 2024
CVE-2024-7346MEDIUM4.8
  • Progress OpenEdge logoProgress OpenEdge
  • cpe:2.3:a:progress:openedge
NoYesSep 03, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management