Site icon API Security Blog

PT-2025-31201 · Progress · Hybrid Data Pipeline Server

image
Name of the Vulnerable Software and Affected Versions: Progress Software Hybrid Data Pipeline Server versions 4.6.2.3226 and below Description: The Hybrid Data Pipeline Server is susceptible to unauthorized access and impersonation. Attackers can combine credentials from multiple sources, potentially leading to client impersonation and unauthorized access. During an OAuth handshake, the server accepts client credentials from both HTTP headers and request parameters. Recommendations: Update to a version later than…Read More

Exit mobile version