A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2024-09 |
|
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-02T01:59:50.072Z
Reserved: 2024-04-05T13:59:17.190Z
Link: CVE-2024-31849
Updated: 2024-08-02T01:59:50.072Z
Status : Awaiting Analysis
Published: 2024-04-05T18:15:09.563
Modified: 2024-11-21T09:14:01.217
Link: CVE-2024-31849
No data.
OpenCVE Enrichment
No data.
Weaknesses