Lucene search

K
cve[email protected]CVE-2019-10246
HistoryApr 22, 2019 - 8:29 p.m.

CVE-2019-10246

2019-04-2220:29:00
CWE-200
CWE-213
web.nvd.nist.gov
72
cve-2019-10246
eclipse jetty
windows
directory listing
remote exposure
nvd
security vulnerability

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.6 Medium

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

84.1%

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

Affected configurations

NVD
Node
eclipsejettyMatch9.2.2720190403
OR
eclipsejettyMatch9.3.2620190403
OR
eclipsejettyMatch9.4.1620190411
AND
microsoftwindowsMatch-
Node
netapponcommand_system_managerRange3.03.1.3
OR
netappsnap_creator_frameworkMatch-
OR
netappsnapcenterMatch-
OR
netappsnapmanagerMatch--oracle
OR
netappsnapmanagerMatch--sap
OR
netappstorage_replication_adapter_for_clustered_data_ontapRange9.6vmware_vsphere
OR
netappstorage_replication_adapter_for_clustered_data_ontapMatch9.6
OR
netappstorage_services_connectorMatch-
OR
netappvasa_provider_for_clustered_data_ontapRange9.6
OR
netappvasa_provider_for_clustered_data_ontapMatch-
OR
netappvirtual_storage_consoleRange9.6vmware_vsphere
OR
netappvirtual_storage_consoleMatch9.6
OR
netappelementMatch-vcenter_server
Node
oracleautovueMatch21.0.2
OR
oraclecommunications_analyticsMatch12.1.1
OR
oraclecommunications_element_managerMatch8.0.0
OR
oraclecommunications_element_managerMatch8.1.0
OR
oraclecommunications_element_managerMatch8.1.1
OR
oraclecommunications_element_managerMatch8.2.0
OR
oraclecommunications_services_gatekeeperMatch6.0
OR
oraclecommunications_services_gatekeeperMatch6.1
OR
oraclecommunications_services_gatekeeperMatch7.0
OR
oraclecommunications_session_report_managerMatch8.0.0
OR
oraclecommunications_session_report_managerMatch8.1.0
OR
oraclecommunications_session_report_managerMatch8.1.1
OR
oraclecommunications_session_report_managerMatch8.2.0
OR
oraclecommunications_session_route_managerMatch8.0.0
OR
oraclecommunications_session_route_managerMatch8.1.0
OR
oraclecommunications_session_route_managerMatch8.1.1
OR
oraclecommunications_session_route_managerMatch8.2.0
OR
oracledata_integratorMatch12.2.1.3.0
OR
oracledata_integratorMatch12.2.1.4.0
OR
oracleendeca_information_discovery_integratorMatch3.2.0
OR
oracleenterprise_manager_base_platformMatch13.2
OR
oracleenterprise_manager_base_platformMatch13.3
OR
oracleflexcube_core_bankingRange11.5.011.7.0
OR
oracleflexcube_core_bankingMatch5.2.0
OR
oracleflexcube_private_bankingMatch12.0.0
OR
oracleflexcube_private_bankingMatch12.1.0
OR
oraclehospitality_guest_accessMatch4.2.0
OR
oraclehospitality_guest_accessMatch4.2.1
OR
oraclerest_data_servicesMatch11.2.0.4-
OR
oraclerest_data_servicesMatch12.1.0.2-
OR
oraclerest_data_servicesMatch12.2.0.1-
OR
oraclerest_data_servicesMatch18c-
OR
oracleretail_xstore_point_of_serviceMatch7.1
OR
oracleretail_xstore_point_of_serviceMatch15.0
OR
oracleretail_xstore_point_of_serviceMatch16.0
OR
oracleretail_xstore_point_of_serviceMatch17.0
OR
oracleunified_directoryMatch12.2.1.3.0
OR
oracleunified_directoryMatch12.2.1.4.0

CNA Affected

[
  {
    "product": "Eclipse Jetty",
    "vendor": "The Eclipse Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "9.2.27"
      },
      {
        "status": "affected",
        "version": "9.3.26"
      },
      {
        "status": "affected",
        "version": "9.4.16"
      }
    ]
  }
]

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.6 Medium

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

84.1%