Feedback
Did this article resolve your question/issue?

   

Article

Progress DataDirect ODBC 8.0 Services installed without double quotes in the "path to executable"

Information

 
TitleProgress DataDirect ODBC 8.0 Services installed without double quotes in the "path to executable"
URL NameProgress-DataDirect-ODBC-8-0-services-installed-without-double-quotes-in-path-to-executable
Article Number000140619
EnvironmentProduct: Progress DataDirect for ODBC for Apache Cassandra Driver
Version: 8.0.0.13 (Cassandra service)
Product: Progress DataDirect for ODBC for MongoDB Driver
Version: 8.0.1.32 (MongoDB service)
OS: Windows
Database: Cassandra, MongoDB
Question/Problem Description
Qualys vulnerability, Windows Unquoted/Trusted Service Paths Privilege Escalation Security Issue, QID 105484

Progress DataDirect Services installed missing the double quotes in "path to executable" in services.msc
This issue has been identified for these services:
Progress DataDirect Apache Cassandra SQL Engine
Progress DataDirect MongoDB SQL Engine

The following article talks about how having unquoted service paths can be a vulnerability: http://www.commonexploits.com/unquoted-service-paths/ 
 
Steps to Reproduce1) Install the driver
2) After the installation, in services.msc. open the service properties and look at the "Path to executable" location.

Observed Results:
The path is C:\Program Files\Progress\DataDirect\<installdir>\tools\<SQL Engine service>.exe /name="Progress DataDirect <driver> SQL Engine"

Expected Results:
The path should be "C:\Program Files\Progress\DataDirect\<installdir>\tools\<SQL Engine service>.exe" /name="Progress DataDirect <driver> SQL Engine"
Clarifying Information
This vulnerability affects ODBC drivers installed on Windows platforms.
Error Message
Defect NumberDefects XDBC-8105, XDBC-9828 (Cassandra) and XDBC-8035, XDBC-9238 (MongoDB)
Enhancement Number
Cause
The SQL Engine service and installer were not configured to double-quote the path to executable.
Resolution
Fixed in hot fix 8.0.0.101 (Cassandra driver) and 8.0.0.48 (Cassandra Service).
Fixed in hot fix 8.0.1.194 (MongoDB driver) and 8.1.1.36 (MongoDB Service).
Refer to  Connect and Connect64 for ODBC hot fix download and install instructions for instructions on how to download and install the hot fix.
Workaround
Notes
Last Modified Date11/20/2020 7:06 AM
Files
Disclaimer The origins of the information on this site may be internal or external to Progress Software Corporation (“Progress”). Progress Software Corporation makes all reasonable efforts to verify this information. However, the information provided is for your information only. Progress Software Corporation makes no explicit or implied claims to the validity of this information.

Any sample code provided on this site is not supported under any Progress support program or service. The sample code is provided on an "AS IS" basis. Progress makes no warranties, express or implied, and disclaims all implied warranties including, without limitation, the implied warranties of merchantability or of fitness for a particular purpose. The entire risk arising out of the use or performance of the sample code is borne by the user. In no event shall Progress, its employees, or anyone else involved in the creation, production, or delivery of the code be liable for any damages whatsoever (including, without limitation, damages for loss of business profits, business interruption, loss of business information, or other pecuniary loss) arising out of the use of or inability to use the sample code, even if Progress has been advised of the possibility of such damages.