CData records
7 published records for vendor cdata.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2024-31848Proof of concept | A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, whiccdata · api server · CWE-22 | Critical9.8 | — | 8.1% | Apr 5, 2024 |
41Plan | CVE-2024-31849Proof of concept | A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which ccdata · connect · CWE-22 | Critical9.8 | — | 6.1% | Apr 5, 2024 |
40Plan | CVE-2020-29056No exploit | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104,cdata · fd1104 firmware · CWE-78 | Critical9.8 | — | 2.0% | Nov 24, 2020 |
35Monitor | CVE-2024-31850Proof of concept | A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which couldcdata · arc · CWE-22 | High8.6 | — | 3.0% | Apr 5, 2024 |
35Monitor | CVE-2024-31851Proof of concept | A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which coulcdata · sync · CWE-22 | High8.6 | — | 2.9% | Apr 5, 2024 |
31Monitor | CVE-2023-24243Proof of concept | CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).cdata · arc · CWE-918 | High7.5 | — | 4.0% | Jun 16, 2023 |
17Monitor | CVE-2025-9273No exploit | CData API Server MySQL Misconfiguration Information Disclosure Vulnerabilitycdata · api server · CWE-552 | Medium4.3 | — | 0.4% | Sep 2, 2025 |
- CVE-2024-3184841Plan
A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, whic
CriticalCVSS 9.8Proof of conceptEPSS 8%cdata · api serverApr 5, 2024
- CVE-2024-3184941Plan
A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which c
CriticalCVSS 9.8Proof of conceptEPSS 6%cdata · connectApr 5, 2024
- CVE-2020-2905640Plan
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104,
CriticalCVSS 9.8No exploitEPSS 2%cdata · fd1104 firmwareNov 24, 2020
- CVE-2024-3185035Monitor
A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could
HighCVSS 8.6Proof of conceptEPSS 3%cdata · arcApr 5, 2024
- CVE-2024-3185135Monitor
A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which coul
HighCVSS 8.6Proof of conceptEPSS 3%cdata · syncApr 5, 2024
- CVE-2023-2424331Monitor
CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).
HighCVSS 7.5Proof of conceptEPSS 4%cdata · arcJun 16, 2023
- CVE-2025-927317Monitor
CData API Server MySQL Misconfiguration Information Disclosure Vulnerability
MediumCVSS 4.3No exploitEPSS 0%cdata · api serverSep 2, 2025