Progress Vulnerabilities and Affected Products
Vulnerabilities associated with LoadMaster.
Products
Clear product- MOVEit Transfer22 vulnerabilities
- whatsup_gold21 vulnerabilities
- LoadMaster11 vulnerabilities
- telerik_reporting8 vulnerabilities
- ws_ftp_server6 vulnerabilities
- openedge5 vulnerabilities
- whatsupgold5 vulnerabilities
- ui_for_wpf4 vulnerabilities
- moveit_transfer3 vulnerabilities
- ShareFile Storage Zones Controller3 vulnerabilities
- sitefinity3 vulnerabilities
- WhatsUp Gold3 vulnerabilities
- DataDirect Connect for JDBC Autonomous REST Connector2 vulnerabilities
- DataDirect Connect for JDBC for Amazon Redshift2 vulnerabilities
- DataDirect Connect for JDBC for Apache Cassandra2 vulnerabilities
- DataDirect Connect for JDBC for Apache Impala2 vulnerabilities
- DataDirect Connect for JDBC for Apache SparkSQL2 vulnerabilities
- DataDirect Connect for JDBC for DB22 vulnerabilities
- DataDirect Connect for JDBC for Google Analytics 42 vulnerabilities
- DataDirect Connect for JDBC for Google BigQuery2 vulnerabilities
- DataDirect Connect for JDBC for Greenplum2 vulnerabilities
- DataDirect Connect for JDBC for Hive2 vulnerabilities
- DataDirect Connect for JDBC for Informix2 vulnerabilities
- DataDirect Connect for JDBC for Microsoft Dynamics 3652 vulnerabilities
- DataDirect Connect for JDBC for Microsoft Sharepoint2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-8037CRITICAL | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAFOS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints | CVSS9.6v3.1 | EPSS99.3% | PoCs2 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2025-1758MEDIUM | Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above CWE-121Mar 19, 2025 | CVSS4.3v3.1 | EPSS4.79% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-56135HIGH | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1 (inclusive) CWE-20Feb 5, 2025 | CVSS8.4v3.1 | EPSS0.591% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-56134HIGH | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12 and all prior versions ECS All prior versions to 7.2.60.1 (inclusive) CWE-20Feb 5, 2025 | CVSS8.4v3.1 | EPSS0.591% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-56133HIGH | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1 (inclusive) CWE-20Feb 5, 2025 | CVSS8.4v3.1 | EPSS0.591% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-56132HIGH | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1 (inclusive) | CVSS8.4v3.1 | EPSS6.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-56131HIGH | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12 and all prior versions ECS All prior versions to 7.2.60.1 (inclusive) CWE-20Feb 5, 2025 | CVSS8.4v3.1 | EPSS6.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8755HIGH | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12 and all prior versions ECS All prior versions to 7.2.60.1 (inclusive) | CVSS8.4v3.1 | EPSS1.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6658HIGH | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.0 (inclusive) From 7.2.49.0 to 7.2.54.11 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.11 and all prior versions ECS All prior versions to 7.2.60.0 (inclusive) CWE-20Sep 12, 2024 | CVSS8.4v3.1 | EPSS0.553% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-7591CRITICAL | Improper Input Validation vulnerability in Progress LoadMaster allows OS Command InjectionImproper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above | CVSS10.0v3.1 | EPSS43.8% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-2449HIGH | LoadMaster Cross-Site Request Forgery (CSRF)A cross-site request forgery vulnerability has been identified in LoadMaster. It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a scenario, the CSRF payload hosted on the malicious site would execute HTTP transactions on behalf of the LoadMaster administrator. CWE-352Mar 22, 2024 | CVSS7.5v3.1 | EPSS12.9% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |