Cdata develops API server and connectivity middleware products, along with embedded firmware components, where disclosures cluster around information exposure and command-injection vulnerabilities affecting file access and OS-level command handling. The recurring weakness classes—including accessible file directories, OS command injection, and server-side request forgery—reflect the attack surface inherent to data-integration and request-processing layers. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cdata over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-31850HIGH A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacke | Apr 5, 2024 | 8.6 | 37 | NO | YES |
CVE-2023-24243HIGH CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF). | Jun 16, 2023 | 7.5 | 34 | NO | YES |
CVE-2020-29056CRITICAL An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD | Nov 24, 2020 | 9.8 | 24 | NO | NO |
CVE-2025-9273MEDIUM CData API Server MySQL Misconfiguration Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations | Sep 2, 2025 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cdata.
Media articles that mention a CVE ID that affects a product developed by Cdata — matched by CVE ID, not by vendor name.