Code Injection Vulnerability in Progress DataDirect JDBC Drivers
CVE-2025-10703
What is CVE-2025-10703?
The vulnerability in Progress DataDirect JDBC drivers allows remote attackers to exploit the SpyAttribute connection option, enabling them to write malicious code into log files. If these files are served by an application server, it could lead to unauthorized code execution, facilitating a range of potential security threats on affected systems. Multi-version exploitation and subsequent impacts on data integrity are noteworthy concerns for all users of the specified drivers.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DataDirect Connect for JDBC Autonomous REST Connector 0 <= 6.0.1.006961
DataDirect Connect for JDBC for Amazon Redshift 0 <= 6.0.0.001392
DataDirect Connect for JDBC for Apache Cassandra 0 <= 6.0.0.000805
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
