Description
Multiple CData products have a path traversal vulnerability, when running using the embedded Jetty server. An unauthenticated attacker can bypass the authentication with a specially crafted HTTP request and get access to sensitive information and some administrative endpoints of the system.
Remediation
Upgrade to the latest version of CData software
References
Related Vulnerabilities
Oracle Database Server CVE-2008-1821 Vulnerability (CVE-2008-1821)
SharePoint CVE-2023-33159 Vulnerability (CVE-2023-33159)
MySQL CVE-2019-2482 Vulnerability (CVE-2019-2482)
TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3942)
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2717)