Lucene search

K
cveMitreCVE-2009-4609
HistoryJan 13, 2010 - 8:30 p.m.

CVE-2009-4609

2010-01-1320:30:00
CWE-200
mitre
web.nvd.nist.gov
39
cve-2009-4609
mort bay jetty
information disclosure
remote attack
security vulnerability

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

5

Confidence

High

EPSS

0.005

Percentile

77.1%

The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other data via a request to a URI ending in /dump/, as demonstrated by discovering the value of the getPathTranslated variable.

Affected configurations

Nvd
Node
mortbayjettyMatch6.0.0
OR
mortbayjettyMatch6.0.0alpha0
OR
mortbayjettyMatch6.0.0alpha1
OR
mortbayjettyMatch6.0.0alpha2
OR
mortbayjettyMatch6.0.0alpha3
OR
mortbayjettyMatch6.0.0beta0
OR
mortbayjettyMatch6.0.0beta1
OR
mortbayjettyMatch6.0.0beta10
OR
mortbayjettyMatch6.0.0beta11
OR
mortbayjettyMatch6.0.0beta12
OR
mortbayjettyMatch6.0.0beta14
OR
mortbayjettyMatch6.0.0beta15
OR
mortbayjettyMatch6.0.0beta16
OR
mortbayjettyMatch6.0.0beta17
OR
mortbayjettyMatch6.0.0beta2
OR
mortbayjettyMatch6.0.0beta3
OR
mortbayjettyMatch6.0.0beta4
OR
mortbayjettyMatch6.0.0beta5
OR
mortbayjettyMatch6.0.0beta6
OR
mortbayjettyMatch6.0.0beta7
OR
mortbayjettyMatch6.0.0beta8
OR
mortbayjettyMatch6.0.0beta9
OR
mortbayjettyMatch6.0.0betax
OR
mortbayjettyMatch6.0.0rc0
OR
mortbayjettyMatch6.0.0rc1
OR
mortbayjettyMatch6.0.0rc2
OR
mortbayjettyMatch6.0.0rc3
OR
mortbayjettyMatch6.0.0rc4
OR
mortbayjettyMatch6.0.1
OR
mortbayjettyMatch6.0.2
OR
mortbayjettyMatch6.1.0
OR
mortbayjettyMatch6.1.0pre0
OR
mortbayjettyMatch6.1.0pre1
OR
mortbayjettyMatch6.1.0pre2
OR
mortbayjettyMatch6.1.0pre3
OR
mortbayjettyMatch6.1.0rc0
OR
mortbayjettyMatch6.1.0rc1
OR
mortbayjettyMatch6.1.0rc2
OR
mortbayjettyMatch6.1.0rc3
OR
mortbayjettyMatch6.1.1
OR
mortbayjettyMatch6.1.1rc0
OR
mortbayjettyMatch6.1.2
OR
mortbayjettyMatch6.1.2pre0
OR
mortbayjettyMatch6.1.2pre1
OR
mortbayjettyMatch6.1.2rc0
OR
mortbayjettyMatch6.1.2rc1
OR
mortbayjettyMatch6.1.2rc2
OR
mortbayjettyMatch6.1.2rc3
OR
mortbayjettyMatch6.1.2rc4
OR
mortbayjettyMatch6.1.2rc5
OR
mortbayjettyMatch6.1.3
OR
mortbayjettyMatch6.1.4
OR
mortbayjettyMatch6.1.4rc0
OR
mortbayjettyMatch6.1.4rc1
OR
mortbayjettyMatch6.1.5
OR
mortbayjettyMatch6.1.5rc0
OR
mortbayjettyMatch6.1.6
OR
mortbayjettyMatch6.1.6rc0
OR
mortbayjettyMatch6.1.6rc1
OR
mortbayjettyMatch6.1.7
OR
mortbayjettyMatch6.1.8
OR
mortbayjettyMatch6.1.9
OR
mortbayjettyMatch6.1.10
OR
mortbayjettyMatch6.1.11
OR
mortbayjettyMatch6.1.12
OR
mortbayjettyMatch6.1.12rc1
OR
mortbayjettyMatch6.1.12rc2
OR
mortbayjettyMatch6.1.12rc3
OR
mortbayjettyMatch6.1.12rc4
OR
mortbayjettyMatch6.1.12rc5
OR
mortbayjettyMatch6.1.14
OR
mortbayjettyMatch6.1.15
OR
mortbayjettyMatch6.1.15pre0
OR
mortbayjettyMatch6.1.15rc2
OR
mortbayjettyMatch6.1.15rc3
OR
mortbayjettyMatch6.1.15rc4
OR
mortbayjettyMatch6.1.15rc5
OR
mortbayjettyMatch6.1.16
OR
mortbayjettyMatch6.1.19
OR
mortbayjettyMatch6.1.20
OR
mortbayjettyMatch7.0.0
VendorProductVersionCPE
mortbayjetty6.0.0cpe:2.3:a:mortbay:jetty:6.0.0:*:*:*:*:*:*:*
mortbayjetty6.0.0cpe:2.3:a:mortbay:jetty:6.0.0:alpha0:*:*:*:*:*:*
mortbayjetty6.0.0cpe:2.3:a:mortbay:jetty:6.0.0:alpha1:*:*:*:*:*:*
mortbayjetty6.0.0cpe:2.3:a:mortbay:jetty:6.0.0:alpha2:*:*:*:*:*:*
mortbayjetty6.0.0cpe:2.3:a:mortbay:jetty:6.0.0:alpha3:*:*:*:*:*:*
mortbayjetty6.0.0cpe:2.3:a:mortbay:jetty:6.0.0:beta0:*:*:*:*:*:*
mortbayjetty6.0.0cpe:2.3:a:mortbay:jetty:6.0.0:beta1:*:*:*:*:*:*
mortbayjetty6.0.0cpe:2.3:a:mortbay:jetty:6.0.0:beta10:*:*:*:*:*:*
mortbayjetty6.0.0cpe:2.3:a:mortbay:jetty:6.0.0:beta11:*:*:*:*:*:*
mortbayjetty6.0.0cpe:2.3:a:mortbay:jetty:6.0.0:beta12:*:*:*:*:*:*
Rows per page:
1-10 of 811

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

5

Confidence

High

EPSS

0.005

Percentile

77.1%