Back to Database
Status published
Critical
CVE-2024-31848
A path traversal vulnerability exists in the Java version of...
Vulnerability Description
A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-31848
Credits & Attribution
No credits recorded in the NVD database.
More from CData
View All →CVE-2025-9273
CData API Server MySQL Misconfiguration Information Disclosure Vulnerability
Medium
4.3
CVE-2024-31851
A path traversal vulnerability exists in the Java version of...
High
8.6
CVE-2024-31850
A path traversal vulnerability exists in the Java version of...
High
8.6
CVE-2024-31849
A path traversal vulnerability exists in the Java version of...
Critical
9.8
Affected Vendor
CData
View all reports →Affected Software
API Server
Vulnerable Versions:
0
Timeline
Official Publish:
April 5th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H