CVE-2025-8095

The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications.  OECH1 encodings should be considered exploitable and immediately replaced by any other supported prefix encoding, all of which are based on symmetric encryption.

Scoring

Severity
CRITICAL
CVSS base score
9.1
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/AU:Y/V:D/RE:M/U:Red
EPSS probability
0.22%
CWE
CWE-257
Published
2026-04-14
Last modified
2026-04-15

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs