Rest Data Services

Vendor:

First CVE: Jun 16, 2017 · Active for 9 years

34
Total CVEs
More Total CVEs than 96% of tracked products
4.9
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
2.9%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Rest Data Services over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2017
9 years ago
Most Recent CVE
May 28, 2026
57 days ago

CVE Severity & Scoring

Rest Data Services34 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local3 (8.8%)
Network30 (88.2%)
Unknown0 (0.0%)
Physical1 (2.9%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (91.2%)
High3 (8.8%)
Unknown0 (0.0%)
User Interaction
None22 (64.7%)
Unknown0 (0.0%)
Required12 (35.3%)
Privileges Required
Low6 (17.6%)
High0 (0.0%)
None28 (82.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (34 CVEs).

34 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's
Apr 29, 20206.195YESYES
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or byp
Jul 15, 20215.391NOYES
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob
Apr 20, 20196.178NOYES
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB
Jun 9, 20215.374NOYES
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality
Feb 26, 20215.361NONO
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
Apr 1, 20217.554NONO
Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unaut
May 28, 202610.043NONO
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execut
Oct 26, 20216.142NONO
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may e
Oct 26, 20216.142NONO
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers
Jun 26, 20189.841NONO

Exploit Exposure

Signals from CVEs in this product scope (34 CVEs).

CISA KEV
1 CVE
2.9% of CVEs· 96th percentile
Metasploit
1 CVE
2.9% of CVEs· 96th percentile
Nuclei
2 CVEs
5.9% of CVEs· 97th percentile
ExploitDB
3 CVEs
8.8% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (34 CVEs).

Media Mentions

Signals from CVEs in this product scope (34 CVEs).

Top CNAs Publishing CVEs For Rest Data Services

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
24.2.016.10.1%00
22.1.136.129.4%00
21.314.810.6%00
21.2.416.12.2%00
19c45.843.3%12
18c96.825.5%12
12.2.0.196.825.5%12
12.1.0.296.825.5%12
11.2.0.496.825.5%12