CVE-2025-6504

Possibilities of IP Spoofing via X-Forwarded-For (XFF) Header

Description

In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header.  Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized access if the spoofed IP matched a whitelisted range. This vulnerability could be exploited to bypass IP restrictions, though valid user credentials would still be required for resource access.

Remediation

Solution:

  • Update the HDP Server to version 4.6.2.2978 or later.

Category

8.4
CVSS
Severity: High
CVSS 3.1 •
EPSS 0.02%
Affected: Progress Software Hybrid Data Pipeline
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2025-6504?
CVE-2025-6504 has been scored as a high severity vulnerability.
How to fix CVE-2025-6504?
To fix CVE-2025-6504: Update the HDP Server to version 4.6.2.2978 or later.
Is CVE-2025-6504 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2025-6504 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2025-6504?
CVE-2025-6504 affects Progress Software Hybrid Data Pipeline.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.