CNNVD-202507-3607 Information

CNNVD ID

CNNVD-202507-3607

CVE-2025-6504

  • CNNVD Published: 2025-07-29

Description (Chinese)

Progress Hybrid Data Pipeline Server是美国Progress公司的一个数据管道服务器。 Progress Hybrid Data Pipeline Server 4.6.2.2978之前版本存在安全漏洞,该漏洞源于X-Forwarded-For标头可能被伪造,可能导致未授权访问。

Description (English)

Progress Hybrid Data Pipeline Server is a data conduit server for Progress. Progress Hybrid Data Pipeline Server 4.6.2.2978 had a security loophole, which stemmed from the possible forgery of the X-Forwarded-For marker, which could lead to unauthorized access.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

Progress

Published

2025-07-29

Last Modified

2026-02-24

References

https://community.progress.com/s/article/DataDirect-Hybrid-Data-Pipeline-Critical-Security-Product-Alert-Bulletin-July-2025—CVE-2025-6504

Patch

https://community.progress.com/s/article/DataDirect-Hybrid-Data-Pipeline-Critical-Security-Product-Alert-Bulletin-July-2025---CVE-2025-6504

Share on: