CData Vulnerabilities and Affected Products
Vulnerabilities associated with api_server.
Products
Clear product- API Server2 vulnerabilities
- api_server1 vulnerability
- Arc1 vulnerability
- Connect1 vulnerability
- Sync1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-31848CRITICAL | CData API Server < 23.4.8844 - Path TraversalA path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application. | CVSS9.8v3.1 | EPSS8.09% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |