Progress LoadMaster
cpe:2.3:a:progress:loadmaster:*:*:*:*:*:*:*
- <= 7.2.62.0
- <= 7.2.54.15
- <= 7.1.35.11
A remote code execution vulnerability has been identified in the Progress LoadMaster API. This issue arises from unsanitized input in the API parameters, allowing an authenticated attacker with 'User Administration' permissions to execute arbitrary commands on the LoadMaster appliance.
Exploitation of this vulnerability allows for command injection, enabling authenticated attackers to execute arbitrary commands on the affected LoadMaster appliance.
A patch for this vulnerability has been released and is available for download. Instructions for updating LoadMaster can be found in the 'Updating the LoadMaster Software' technical note on the Progress Community Portal. Customers under a current support contract can also contact Progress Technical Support for assistance.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.