Unauthorized Access Vulnerability in HDP Server by Progress Software
CVE-2025-6504
8.4HIGH
What is CVE-2025-6504?
The HDP Server prior to version 4.6.2.2978 on Linux systems is susceptible to an unauthorized access vulnerability due to IP spoofing through the X-Forwarded-For header. This client-controlled header can be manipulated to simulate requests from whitelisted IPs, potentially allowing unauthorized users to bypass pre-set IP restrictions. Although valid user credentials are still necessary for resource access, the exploitation of this vulnerability creates a significant security risk that must be addressed.
Affected Version(s)
Hybrid Data Pipeline Linux 0 < 4.6.2.2978