Unauthorized Access Vulnerability in HDP Server by Progress Software
CVE-2025-6504

8.4HIGH

Key Information:

Vendor
CVE Published:
29 July 2025

What is CVE-2025-6504?

The HDP Server prior to version 4.6.2.2978 on Linux systems is susceptible to an unauthorized access vulnerability due to IP spoofing through the X-Forwarded-For header. This client-controlled header can be manipulated to simulate requests from whitelisted IPs, potentially allowing unauthorized users to bypass pre-set IP restrictions. Although valid user credentials are still necessary for resource access, the exploitation of this vulnerability creates a significant security risk that must be addressed.

Affected Version(s)

Hybrid Data Pipeline Linux 0 < 4.6.2.2978

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6504 : Unauthorized Access Vulnerability in HDP Server by Progress Software