Code Injection Vulnerability in Progress DataDirect JDBC Drivers
CVE-2025-10702
What is CVE-2025-10702?
A vulnerability in Progress DataDirect JDBC drivers allows for remote code inclusion due to improper handling of the SpyAttributes connection option. Attackers could exploit this flaw through an undocumented syntax, leading to the execution of arbitrary classes and constructors. This potentially impacts numerous applications that rely on these JDBC drivers for database connectivity. Users are advised to upgrade their drivers to the latest patched versions to safeguard against such exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DataDirect Connect for JDBC Autonomous REST Connector 0 <= 6.0.1.006961
DataDirect Connect for JDBC for Amazon Redshift 0 <= 6.0.0.001392
DataDirect Connect for JDBC for Apache Cassandra 0 <= 6.0.0.000805
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
