cbcvebase.

Oracle Rest Data Services vulnerabilities

34 known vulnerabilities affecting oracle/rest_data_services.

Total CVEs
34
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
4
Severity breakdown
CRITICAL5HIGH5MEDIUM23LOW1

Vulnerabilities

Page 2 of 2
CVE-2021-29425P4MEDIUMCVSS 4.8fixed in 21.2v21.32021-04-13
CVE-2021-29425 [MEDIUM] CWE-20 CVE-2021-29425: In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper i In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to constru
nvd
CVE-2020-27218P4MEDIUMCVSS 4.8fixed in 20.4.3.050.19042020-11-28
CVE-2020-27218 [MEDIUM] CWE-226 CVE-2020-27218: In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.al In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the applicati
nvd
CVE-2019-10246P4MEDIUMCVSS 5.3v11.2.0.4v12.1.0.2+2 more2019-04-22
CVE-2019-10246 [MEDIUM] CWE-213 CVE-2019-10246: In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource dire
nvd
CVE-2026-46841P4MEDIUMCVSS 5.3≥ 24.2.0, ≤ 26.1.02026-05-28
CVE-2026-46841 [MEDIUM] CWE-200 CVE-2026-46841: Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affect Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized read access to a subset of
nvd
CVE-2026-46830P4MEDIUMCVSS 5.3≥ 24.2.0, ≤ 26.1.02026-05-28
CVE-2026-46830 [MEDIUM] CWE-200 CVE-2026-46830: Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affec Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized read access to a subset of
nvd
CVE-2026-46842P4MEDIUMCVSS 5.3≥ 24.2.0, ≤ 26.1.02026-05-28
CVE-2026-46842 [MEDIUM] CWE-284 CVE-2026-46842: Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access
nvd
CVE-2026-46843P4MEDIUMCVSS 5.3≥ 24.2.0, ≤ 26.1.02026-05-28
CVE-2026-46843 [MEDIUM] CWE-400 CVE-2026-46843: Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial deni
nvd
CVE-2025-30756P4MEDIUMCVSS 6.1v24.2.02025-07-15
CVE-2025-30756 [MEDIUM] CWE-352 CVE-2025-30756: Vulnerability in Oracle REST Data Services (component: General). The supported version that is aff Vulnerability in Oracle REST Data Services (component: General). The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle REST Data Services. Successful attacks require human interaction from a person other than the attacker and while the vulner
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v21.2.42019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2020-14745P4MEDIUMCVSS 4.3fixed in 20.2.1v11.2.0.4+4 more2020-10-21
CVE-2020-14745 [MEDIUM] CVE-2020-14745: Vulnerability in the Oracle REST Data Services product of Oracle REST Data Services (component: Gene Vulnerability in the Oracle REST Data Services product of Oracle REST Data Services (component: General). Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c; Standalone ORDS: prior to 20.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle REST Data Services. S
nvd
CVE-2021-32012P4MEDIUMCVSS 5.5fixed in 21.2.42021-07-19
CVE-2021-32012 [MEDIUM] CWE-400 CVE-2021-32012: SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consump SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).
nvd
CVE-2021-32013P4MEDIUMCVSS 5.5fixed in 21.2.42021-07-19
CVE-2021-32013 [MEDIUM] CWE-400 CVE-2021-32013: SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consump SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 2 of 2).
nvd
CVE-2021-32014P4MEDIUMCVSS 5.5fixed in 21.2.42021-07-19
CVE-2021-32014 [MEDIUM] CWE-400 CVE-2021-32014: SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumptio SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js.
nvd
CVE-2021-34428P4LOWCVSS 3.5fixed in 21.32021-06-22
CVE-2021-34428 [LOW] CWE-613 CVE-2021-34428: For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the Sessi For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application use
nvd
Oracle Rest Data Services vulnerabilities | cvebase