CVE-2025-6505

8.1

Progress Software · Hybrid Data Pipeline

Progress Software Hybrid Data Pipeline is vulnerable to unauthorized access and client impersonation during the OAuth handshake process due to improper handling of client credentials.

Executive summary

A critical vulnerability in Progress Software Hybrid Data Pipeline allows unauthenticated attackers to impersonate clients and gain unauthorized access via credential confusion during OAuth handshakes.

Vulnerability

This vulnerability occurs because the server concurrently accepts OAuth client credentials from both HTTP headers and request parameters, enabling an attacker to manipulate authentication inputs. This flaw allows an unauthenticated remote attacker to bypass intended security controls and impersonate legitimate clients.

Business impact

The ability for an attacker to impersonate legitimate users or clients poses a severe risk to data confidentiality and integrity. Successful exploitation could lead to unauthorized access to sensitive backend data sources integrated through the Hybrid Data Pipeline, potentially resulting in data exfiltration or unauthorized modifications. Given the CVSS score of 8.1, this represents a high-severity risk that requires immediate attention to prevent compromise of integrated enterprise systems.

Remediation

Immediate Action: Upgrade all instances of Progress Software Hybrid Data Pipeline to version 4.6.2.3275 or later to resolve the credential handling flaw.

Proactive Monitoring: Review system access logs for anomalous OAuth handshake patterns or unexpected authentication requests originating from unauthorized sources.

Compensating Controls: Implement strict network access controls or a Web Application Firewall (WAF) to restrict access to the Hybrid Data Pipeline server to known, trusted IP addresses while the update is being staged.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The vulnerability in the Hybrid Data Pipeline server presents a significant risk of unauthorized access due to flawed credential processing. Administrators should prioritize the transition to version 4.6.2.3275 or later immediately. Failure to patch this issue could allow attackers to bypass authentication entirely, leading to potential data breaches within your connected data ecosystems.

More Progress Software CVEs

Sources