Feedback
Did this article resolve your question/issue?

   

Article

Progress DataDirect Services installed without double quotes in the "path to executable" associated with the service is a security concern

Information

 
TitleProgress DataDirect Services installed without double quotes in the "path to executable" associated with the service is a security concern
URL NameProgress-DataDirect-Services-installed-without-double-quotes-in-the-path-to-executable-associated-with-the-service-is-a-security-concern
Article Number000176394
EnvironmentProduct: Connect/Connect64 for ODBC Salesforce driver, Progress DataDirect for ODBC for MongoDB Driver
Version: 7.1
OS: Windows 32-bit, 64-bit
Database: Salesforce, MongoDB
Application: Installer
Question/Problem Description
Progress DataDirect Services installed missing the double quotes in "path to executable" in services.msc
This issue has been identified for the below services
  • Progress DataDirect Salesforce SQL Engine
  • Progress DataDirect MongoDB SQL Engine
The following article talks about how having unquoted service paths can be a vulnerability: http://www.commonexploits.com/unquoted-service-paths/ 
Steps to Reproduce1) Install the Connect64 for ODBC Salesforce driver
2) After the installation, review the services.msc and look at the "Path to executable" location in the Properties for the Progress DataDirect Salesforce SQL Engine service

Observed Results:
The path is C:\Program Files\Progress\DataDirect\Connect64_for_ODBC_71\tools\salesforceserver.exe /name="Progress DataDirect Salesforce SQL Engine"

Expected Results:
The path should be "C:\Program Files\Progress\DataDirect\Connect64_for_ODBC_71\tools\salesforceserver.exe /name="Progress DataDirect Salesforce SQL Engine"
Clarifying Information
Error Message
Defect NumberDefect PSC00335351
Enhancement Number
Cause
Resolution
Fixed in Connect/Connect64 for ODBC 7.1 salesforceserver.exe #18 and Progress DataDirect for ODBC for MongoDB Driver 7.1 mongodbserver.exe #15.

Refer to "Connect and Connect64 for ODBC hot fix download and install instructions" for instructions on how to download and install the hot fix.



 
Workaround
Notes
Last Modified Date11/20/2020 7:05 AM
Files
Disclaimer The origins of the information on this site may be internal or external to Progress Software Corporation (“Progress”). Progress Software Corporation makes all reasonable efforts to verify this information. However, the information provided is for your information only. Progress Software Corporation makes no explicit or implied claims to the validity of this information.

Any sample code provided on this site is not supported under any Progress support program or service. The sample code is provided on an "AS IS" basis. Progress makes no warranties, express or implied, and disclaims all implied warranties including, without limitation, the implied warranties of merchantability or of fitness for a particular purpose. The entire risk arising out of the use or performance of the sample code is borne by the user. In no event shall Progress, its employees, or anyone else involved in the creation, production, or delivery of the code be liable for any damages whatsoever (including, without limitation, damages for loss of business profits, business interruption, loss of business information, or other pecuniary loss) arising out of the use of or inability to use the sample code, even if Progress has been advised of the possibility of such damages.