Progress DataDirect Hybrid Data Pipeline OAuth Credential Mixing Vulnerability Allowing Unauthorized Access and Impersonation
Vulnerability
A vulnerability exists in Progress DataDirect Hybrid Data Pipeline Server versions through 4.6.2.3226 on Linux, allowing unauthorized access and impersonation by mixing OAuth client credentials from HTTP headers and request parameters. This could lead to client impersonation and unauthorized access to OData endpoints.
Impact
Exploitation of this vulnerability could result in unauthorized access to OData endpoints by impersonating clients.
Remediation
Users are advised to upgrade to version 4.6.2.3275. Instructions for downloading and installing the update are available in the Progress Community. Customers not on a current maintenance agreement should contact their Progress account representative.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
