Progress Telerik Security Update – 29 July 2024

Progress Telerik has released a security update to address a critical vulnerability affecting Progress Telerik Report Server versions prior to 2024 Q2 (10.1.24.709).

The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access to the affected system.

Progress Telerik OS Remote Code Execution Vulnerability (CVE-2024-6327):

  • CVSS: 9.9
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2024-6327

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Progress Telerik Security Advisory

References