Progress DataDirect Hybrid Data Pipeline OAuth Credential Mixing Vulnerability Allowing Unauthorized Access and Impersonation

Vulnerability

A vulnerability exists in Progress DataDirect Hybrid Data Pipeline Server versions through 4.6.2.3226 on Linux, allowing unauthorized access and impersonation by mixing OAuth client credentials from HTTP headers and request parameters. This could lead to client impersonation and unauthorized access to OData endpoints.

Impact

Exploitation of this vulnerability could result in unauthorized access to OData endpoints by impersonating clients.

Remediation

Users are advised to upgrade to version 4.6.2.3275. Instructions for downloading and installing the update are available in the Progress Community. Customers not on a current maintenance agreement should contact their Progress account representative.

Added: Jul 29, 2025, 1:18 PM
Updated: Jul 29, 2025, 2:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.