Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client impersonation and unauthorized access.  When OAuth Clients perform an OAuth handshake with the Hybrid Data Pipeline Server, the server accepts client credentials from both HTTP headers and request parameters.
History

Wed, 30 Jul 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress hybrid Data Pipeline
Vendors & Products Progress
Progress hybrid Data Pipeline

Tue, 29 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Jul 2025 13:15:00 +0000

Type Values Removed Values Added
Description Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client impersonation and unauthorized access.  When OAuth Clients perform an OAuth handshake with the Hybrid Data Pipeline Server, the server accepts client credentials from both HTTP headers and request parameters.
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published: 2025-07-29T12:56:57.219Z

Updated: 2025-07-29T13:25:19.719Z

Reserved: 2025-06-23T02:43:50.777Z

Link: CVE-2025-6505

cve-icon Vulnrichment

Updated: 2025-07-29T13:25:16.052Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-29T13:15:28.807

Modified: 2025-07-29T14:15:38.653

Link: CVE-2025-6505

cve-icon Redhat

No data.