April 5, 2024, 1:49 p.m. | Evan Grant

Tenable Research Advisories www.tenable.com

Path Traversal Affecting Multiple CData Products

A researcher at Tenable discovered a path traversal vulnerability affecting the Java versions of multiple CData products when deployed using the embedded Jetty server, with varying impacts per product. The issue exists because of a combination of how the embedded Jetty server and CData servlets handle requests.

Technical Details

The path traversal can be leveraged as a result of the following conditions:

  • The servlet mappings and security constraints laid out in each application's web.xml …

application attachment cookie date encoding evan filename grant http json length options path path traversal products server transfer x-frame-options

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Senior Security Architect - Northwest region (Remote)

@ GuidePoint Security LLC | Remote

Senior Consultant, Cyber Security Architecture

@ 6point6 | Manchester, United Kingdom

Junior Security Architect

@ IQ-EQ | Port Louis, Mauritius

Senior Detection & Response Engineer

@ Expel | Remote

Cyber Security Systems Engineer ISSE Splunk

@ SAP | Southbank (Melbourne), VIC, AU, 3006