PT-2024-2869 · Eclipse+1 · Jetty+1

Evan Grant

·

Published

2024-03-04

·

Updated

2024-05-10

·

CVE-2024-31850

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions CData Arc versions prior to 23.4.8839
Description A path traversal vulnerability exists in the Java version of CData Arc when running using the embedded Jetty server. This could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions by sending specially crafted HTTP requests. The vulnerability is related to errors in handling relative path to directory.
Recommendations For versions prior to 23.4.8839, update to version 23.4.8839 or later to resolve the issue. As a temporary workaround, consider restricting access to the embedded Jetty server until a patch is available. Avoid using the vulnerable server for sensitive operations until the issue is resolved.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-03030
CVE-2024-31850

Affected Products

Cdata Arc
Jetty