PT-2025-51263 · Edb+1 · Hybrid Manager - Lts+3
Published
2025-12-15
·
Updated
2026-02-18
·
CVE-2025-14038
CVSS v3.1
7.0
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
EDB Hybrid Manager versions prior to 1.3.3
EDB Hybrid Manager - Innovation versions prior to 2025.12
EDB Hybrid Manager - LTS versions prior to 1.3.3
Description
EDB Hybrid Manager has a flaw that allows an unauthenticated attacker to access certain gRPC endpoints directly. This access could allow an attacker to read sensitive data or potentially cause a denial-of-service by sending malformed data to these endpoints. The issue stems from a misconfiguration in the Istio Gateway, which manages authentication and authorization for the affected endpoints. The security policy relies on explicitly defined permissions in the Istio Gateway configuration, but the affected endpoints were not defined, allowing requests to bypass authentication and authorization. The vulnerable endpoints are gRPC endpoints, and access to them does not require authentication.
Recommendations
EDB Hybrid Manager versions prior to 1.3.3 should be upgraded to version 1.3.3.
EDB Hybrid Manager - Innovation versions prior to 2025.12 should be upgraded to version 2025.12.
EDB Hybrid Manager - LTS versions prior to 1.3.3 should be upgraded to version 1.3.3.
Fix
DoS
Missing Authentication
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Edb Hybrid Manager
Hybrid Manager - Innovation
Hybrid Manager - Lts
Istio Gateway