CVE-2025-6505 Details
Description
Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client impersonation and unauthorized access. When OAuth Clients perform an OAuth handshake with the Hybrid Data Pipeline Server, the server accepts client credentials from both HTTP headers and request parameters.
A vulnerability exists in Progress DataDirect Hybrid Data Pipeline Server versions through 4.6.2.3226 on Linux, allowing unauthorized access and impersonation by mixing OAuth client credentials from HTTP headers and request parameters. This could lead to client impersonation and unauthorized access to OData endpoints.
Users are advised to upgrade to version 4.6.2.3275. Instructions for downloading and installing the update are available in the Progress Community. Customers not on a current maintenance agreement should contact their Progress account representative.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.progress.com/s/article/DataDirect-Hybrid-Data-Pipeline-Critical-Security-Product-Alert-Bulletin-July-2025---CVE-2025-6505 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| progress hybrid data pipeline | < 4.6.2.3275 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 2, 2025 | Initial Analysis | [email protected] |
| Jul 29, 2025 | CVE Modified | CISA-ADP |
| Jul 29, 2025 | New CVE Received | [email protected] |