CVE Database
/

CVE-2025-10702

Back to search

CVE-2025-10702

Published: Nov 19, 2025

Modified: Feb 26, 2026

PUBLISHED

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver supports an undocumented syntax construct for the option value that if discovered can be used by an attacker. If an application allows an end user to specify a value for the SpyAttributes connection option then an attacker can use the undocumented syntax to cause the driver to load an arbitrary class on the class path and execute a constructor on that class.   This issue affects: DataDirect Connect for JDBC for Amazon Redshift: through 6.0.0.001392, fixed in 6.0.0.001541 DataDirect Connect for JDBC for Apache Cassandra: through 6.0.0.000805, fixed in 6.0.0.000833 DataDirect Connect for JDBC for Hive: through 6.0.1.001499, fixed in 6.0.1.001628 DataDirect Connect for JDBC for Apache Impala: through 6.0.0.001155, fixed in 6.0.0.001279 DataDirect Connect for JDBC for Apache SparkSQL: through 6.0.1.001222, fixed in 6.0.1.001344 DataDirect Connect for JDBC Autonomous REST Connector: through 6.0.1.006961, fixed in 6.0.1.007063 DataDirect Connect for JDBC for DB2: through 6.0.0.000717, fixed in 6.0.0.000964 DataDirect Connect for JDBC for Google Analytics 4: through 6.0.0.000454, fixed in 6.0.0.000525 DataDirect Connect for JDBC for Google BigQuery: through 6.0.0.002279, fixed in 6.0.0.002410 DataDirect Connect for JDBC for Greenplum: through 6.0.0.001712, fixed in 6.0.0.001727 DataDirect Connect for JDBC for Informix: through 6.0.0.000690, fixed in 6.0.0.0851 DataDirect Connect for JDBC for Microsoft Dynamics 365: through 6.0.0.003161, fixed in 6.0.0.3198 DataDirect Connect for JDBC for Microsoft SQLServer: through 6.0.0.001936, fixed in 6.0.0.001957 DataDirect Connect for JDBC for Microsoft Sharepoint: through 6.0.0.001559, fixed in 6.0.0.001587 DataDirect Connect for JDBC for MongoDB: through 6.1.0.001654, fixed in 6.1.0.001669 DataDirect Connect for JDBC for MySQL: through 5.1.4.000330, fixed in 5.1.4.000364 DataDirect Connect for JDBC for Oracle Database: through 6.0.0.001747, fixed in 6.0.0.001776 DataDirect Connect for JDBC for Oracle Eloqua: through 6.0.0.001438, fixed in 6.0.0.001458 DataDirect Connect for JDBC for Oracle Sales Cloud: through 6.0.0.001225, fixed in 6.0.0.001316 DataDirect Connect for JDBC for Oracle Service Cloud: through 5.1.4.000298, fixed in 5.1.4.000309 DataDirect Connect for JDBC for PostgreSQL: through 6.0.0.001843, fixed in 6.0.0.001856 DataDirect Connect for JDBC for Progress OpenEdge: through 5.1.4.000187, fixed in 5.1.4.000189 DataDirect Connect for JDBC for Salesforce: through 6.0.0.003020, fixed in 6.0.0.003125 DataDirect Connect for JDBC for SAP HANA: through 6.0.0.000879, product retired DataDirect Connect for JDBC for SAP S/4 HANA: through 6.0.1.001818, fixed in 6.0.1.001858 DataDirect Connect for JDBC for Sybase ASE: through 5.1.4.000161, fixed in 5.1.4.000162 DataDirect Connect for JDBC for Snowflake: through 6.0.1.001821, fixed in 6.0.1.001856 DataDirect Hybrid Data Pipeline Server: through 4.6.2.3309, fixed in 4.6.2.3430 DataDirect Hybrid Data Pipeline JDBC Driver: through 4.6.2.0607, fixed in 4.6.2.1023 DataDirect Hybrid Data Pipeline On Premises Connector: through 4.6.2.1223, fixed in 4.6.2.1339 DataDirect Hybrid Data Pipeline Docker: through 4.6.2.3316, fixed in 4.6.2.3430 DataDirect OpenAccess JDBC Driver: through 8.1.0.0177, fixed in 8.1.0.0183 DataDirect OpenAccess JDBC Driver: through 9.0.0.0019, fixed in 9.0.0.0022

VendorProductVersions

Progress

DataDirect Connect for JDBC for Amazon Redshift

affected
0 - <= 6.0.0.001392
unaffected
6.0.0.001541

Progress

DataDirect Connect for JDBC for Apache Cassandra

affected
0 - <= 6.0.0.000805
unaffected
6.0.0.000833

Progress

DataDirect Connect for JDBC for Hive

affected
0 - <= 6.0.1.001499
unaffected
6.0.1.001628

Progress

DataDirect Connect for JDBC for Apache Impala

affected
0 - <= 6.0.0.001155
unaffected
6.0.0.1279

Progress

DataDirect Connect for JDBC for Apache SparkSQL

affected
0 - <= 6.0.1.001222
unaffected
6.0.1.001344

Progress

DataDirect Connect for JDBC Autonomous REST Connector

affected
0 - <= 6.0.1.006961
unaffected
6.0.1.007063

Progress

DataDirect Connect for JDBC for DB2

affected
0 - <= 6.0.0.000717
unaffected
6.0.0.000964

Progress

DataDirect Connect for JDBC for Google Analytics 4

affected
0 - <= 6.0.0.000454
unaffected
6.0.0.000525

Progress

DataDirect Connect for JDBC for Google BigQuery

affected
0 - <= 6.0.0.002279
unaffected
6.0.0.002410

Progress

DataDirect Connect for JDBC for Greenplum

affected
0 - <= 6.0.0.001712
unaffected
6.0.0.001727

Progress

DataDirect Connect for JDBC for Informix

affected
0 - <= 6.0.0.000690
unaffected
6.0.0.000851

Progress

DataDirect Connect for JDBC for Microsoft Dynamics 365

affected
0 - <= 6.0.0.003161
unaffected
6.0.0.003198

Progress

DataDirect Connect for JDBC for Microsoft SQLServer

affected
0 - <= 6.0.0.001936
unaffected
6.0.0.001957

Progress

DataDirect Connect for JDBC for Microsoft Sharepoint

affected
0 - <= 6.0.0.001559
unaffected
6.0.0.001587

Progress

DataDirect Connect for JDBC for MongoDB

affected
0 - <= 6.1.0.001654
unaffected
6.1.0.001669

Progress

DataDirect Connect for JDBC for MySQL

affected
0 - <= 5.1.4.000330
unaffected
5.1.4.000364

Progress

DataDirect Connect for JDBC for Oracle Database

affected
0 - <= 6.0.0.001747
unaffected
6.0.0.001776

Progress

DataDirect Connect for JDBC for Oracle Eloqua

affected
0 - <= 6.0.0.001438
unaffected
6.0.0.001458

Progress

DataDirect Connect for JDBC for Oracle Sales Cloud

affected
0 - <= 6.0.0.001225
unaffected
6.0.0.001316

Progress

DataDirect Connect for JDBC for Oracle Service Cloud

affected
0 - <= 5.1.4.000298
unaffected
5.1.4.000309

Progress

DataDirect Connect for JDBC for PostgreSQL

affected
0 - <= 6.0.0.001843
unaffected
6.0.0.001856

Progress

DataDirect Connect for JDBC for Progress OpenEdge

affected
0 - <= 5.1.4.000187
unaffected
5.1.4.000189

Progress

DataDirect Connect for JDBC for Salesforce

affected
0 - <= 6.0.0.003020
unaffected
6.0.0.003125

Progress

DataDirect Connect for JDBC for SAP HANA

affected
0 - <= 6.0.0.000879

Progress

DataDirect Connect for JDBC for SAP S/4 HANA

affected
0 - <= 6.0.1.001818
unaffected
6.0.1.001858

Progress

DataDirect Connect for JDBC for Sybase ASE

affected
0 - <= 5.1.4.000161
unaffected
5.1.4.000162

Progress

DataDirect Connect for JDBC for Snowflake

affected
0 - <= 6.0.1.001821
unaffected
6.0.1.001856

Progress

DataDirect Hybrid Data Pipeline Server

affected
0 - <= 4.6.2.3309
unaffected
4.6.2.3430

Progress

DataDirect Hybrid Data Pipeline JDBC Driver

affected
0 - <= 4.6.2.0607
unaffected
4.6.2.1023

Progress

DataDirect Hybrid Data Pipeline On Premises Connector

affected
0 - <= 4.6.2.1223
unaffected
4.6.2.1339

Progress

DataDirect Hybrid Data Pipeline Docker

affected
0 - <= 4.6.2.3316
unaffected
4.6.2.3430

Progress

DataDirect OpenAccess JDBC Driver

affected
0 - <= 8.1.0.0177
unaffected
8.1.0.0183

Progress

DataDirect OpenAccess JDBC Driver

affected
0 - <= 9.0.0.0019
unaffected
9.0.0.0022

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now