CVE-2025-8095
CRITICALRecoverable obfuscation using the OECH1 prefix encoding in OpenEdge
Title source: cnaDescription
The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications. OECH1 encodings should be considered exploitable and immediately replaced by any other supported prefix encoding, all of which are based on symmetric encryption.
Scores
CVSS v4
9.1
EPSS
0.0003
EPSS Percentile
8.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/AU:Y/V:D/RE:M/U:Red
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-257
Status
published
Products (2)
Progress Software Corporation/OpenEdge
12.2.0 - 12.2.18
Progress Software Corporation/OpenEdge
12.8.0 - 12.8.9
Published
Apr 14, 2026
Tracked Since
Apr 14, 2026