CVE-2025-6505: High severity Progress Software Hybrid Data Pipeline Server vulnerability
Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client impersonation and unauthorized access. When OAuth Clients perform an OAuth handshake with the Hybrid Data Pipeline Server, the server accepts client credentials from both HTTP headers and request parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress Software Hybrid Data Pipeline Server (Linux)to a version that resolves this vulnerability.Fixed in 4.6.2.3275
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6505?
CVE-2025-6505 is categorized as a critical vulnerability due to the potential for unauthorized access and client impersonation.
How do I fix CVE-2025-6505?
To mitigate CVE-2025-6505, upgrade to version 4.6.2.3227 or later of Progress Software's Hybrid Data Pipeline Server.
What systems are affected by CVE-2025-6505?
CVE-2025-6505 affects versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux.
What kind of attacks can occur due to CVE-2025-6505?
CVE-2025-6505 allows attackers to combine credentials from different sources, leading to unauthorized access and impersonation.
Is there a workaround for CVE-2025-6505?
Currently, the recommended action for CVE-2025-6505 is to upgrade to a patched version instead of relying on workarounds.