Progress LoadMaster
cpe:2.3:a:progress:loadmaster:*:*:*:*:*:*:*
- <= 7.2.62.0
A remote code execution vulnerability has been identified in the Progress LoadMaster API. This issue arises from OS command injection that exploits unsanitized input in the API parameters. The vulnerability affects authenticated users with 'User Administration' permissions, allowing them to execute arbitrary commands on the LoadMaster appliance.
Exploitation of this vulnerability allows for remote code execution on the affected LoadMaster appliance.
A patch for this vulnerability has been released and is available for download. Instructions for updating LoadMaster can be found in the LoadMaster Technical Note on Updating the LoadMaster Software.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.