CVE 8.4 HIGH

Possibilities of IP Spoofing via X-Forwarded-For (XFF) Header_CVE-2025-6504

8.4 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Description

In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header. 

Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized access if the spoofed IP matched a whitelisted range.


This vulnerability could be exploited to bypass IP restrictions, though valid user credentials would still be required for resource access.

Basic Information

ID CVE-2025-6504
Source ProgressSoftware
Published Jul 29, 2025 at 12:56
Modified Jul 29, 2025 at 13:27

Affected Product

Vendor Progress Software
Product Hybrid Data Pipeline
Affected Versions Progress Software Hybrid Data Pipeline 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.