
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-7388 is a Remote Command Execution (RCE) vulnerability in the Progress Software OpenEdge AdminServer, exploitable via its Java RMI interface. Authenticated users with low privileges can inject and execute arbitrary OS commands under the delegated authority of the AdminServer process due to inadequate input validation on a configuration property. Affected versions include OpenEdge 12.2.0 through 12.2.17 (fixed in 12.2.18) and OpenEdge 12.8.0 through 12.8.7 (fixed in 12.8.8). The vulnerability was published on September 4, 2025, and carries a CVSS v3.1 base score of 8.4 (High) (Red Hat CVE, ENISA EUVD).
The root cause is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — Command Injection). The OpenEdge AdminServer exposes a Java RMI interface that allows manipulation of a configuration property; because user-supplied input is not adequately sanitized before being passed to OS-level command execution, an authenticated attacker can inject shell metacharacters or command delimiters to execute arbitrary commands. Exploitation requires network access to the RMI interface and at least low-privilege authentication, but no user interaction. A technical write-up detailing the exploitation path was published by Core Security (Core Security Blog).
Successful exploitation allows an authenticated attacker to execute arbitrary OS commands with the privileges of the AdminServer process, resulting in high confidentiality and integrity impact and low availability impact. An attacker could exfiltrate sensitive data, manipulate system configurations, deploy backdoors, or use the compromised server as a pivot point for lateral movement within the network. The changed scope indicator in the CVSS vector reflects that the impact can extend beyond the AdminServer itself to other components on the host or network (Red Hat CVE, ENISA EUVD).
As of the time of publication, there is no confirmed public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.257%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the vulnerability was featured in security community roundups and trending CVE lists shortly after disclosure, indicating elevated researcher interest (Reddit CVEWatch, The Hacker News).
;, &&, |, or backticks) embedding the desired command (e.g., a reverse shell or data exfiltration command).;, |, &&, backticks); authentication events for low-privilege accounts followed immediately by configuration changes.cmd.exe, powershell.exe, /bin/sh, /bin/bash, curl, wget, nc); processes running under the AdminServer service account performing unexpected actions.Progress Software has released patched versions: OpenEdge 12.2.18 and OpenEdge 12.8.8, which address the inadequate input validation in the RMI interface (ENISA EUVD, Progress Community). Organizations unable to patch immediately should restrict network access to the AdminServer RMI port using firewalls or network segmentation, limiting exposure to only trusted administrative hosts. Additional interim measures include enforcing the principle of least privilege for AdminServer accounts, enabling detailed audit logging of administrative interface access, and monitoring for anomalous configuration changes.
The vulnerability received coverage from multiple security news outlets including CyberSecurityNews, SecurityOnline, and The Hacker News' weekly recap, indicating broad community awareness (CyberSecurityNews, SecurityOnline, The Hacker News). Core Security published a technical blog post detailing the exploitation path, titled "Completing the Circle: Path to CVE-2025-7388" (Core Security Blog). The CVE appeared in a Reddit CVEWatch trending list for the week of September 7, 2025, and was noted in the BornCity blog in the context of its impact on proALPHA ERP systems that use OpenEdge as a backend (BornCity).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."