Lucene search

K
nvd[email protected]NVD:CVE-2017-9735
HistoryJun 16, 2017 - 9:29 p.m.

CVE-2017-9735

2017-06-1621:29:00
CWE-203
web.nvd.nist.gov
14

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.8

Confidence

High

EPSS

0.003

Percentile

69.6%

Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

Affected configurations

Nvd
Node
eclipsejettyRange<9.2.22
OR
eclipsejettyRange9.3.09.3.20
OR
eclipsejettyRange9.4.09.4.6
Node
debiandebian_linuxMatch9.0
Node
oraclecommunications_cloud_native_core_policyMatch1.5.0
OR
oracleenterprise_manager_base_platformMatch13.2
OR
oracleenterprise_manager_base_platformMatch13.3
OR
oraclehospitality_guest_accessMatch4.2.0
OR
oraclehospitality_guest_accessMatch4.2.1
OR
oraclerest_data_servicesMatch11.2.0.4-
OR
oraclerest_data_servicesMatch12.1.0.2-
OR
oraclerest_data_servicesMatch12.2.0.1-
OR
oraclerest_data_servicesMatch18c-
OR
oracleretail_xstore_point_of_serviceMatch7.1
OR
oracleretail_xstore_point_of_serviceMatch15.0
OR
oracleretail_xstore_point_of_serviceMatch16.0
OR
oracleretail_xstore_point_of_serviceMatch17.0
VendorProductVersionCPE
eclipsejetty*cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
debiandebian_linux9.0cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
oraclecommunications_cloud_native_core_policy1.5.0cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.5.0:*:*:*:*:*:*:*
oracleenterprise_manager_base_platform13.2cpe:2.3:a:oracle:enterprise_manager_base_platform:13.2:*:*:*:*:*:*:*
oracleenterprise_manager_base_platform13.3cpe:2.3:a:oracle:enterprise_manager_base_platform:13.3:*:*:*:*:*:*:*
oraclehospitality_guest_access4.2.0cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*
oraclehospitality_guest_access4.2.1cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*
oraclerest_data_services11.2.0.4cpe:2.3:a:oracle:rest_data_services:11.2.0.4:*:*:*:-:*:*:*
oraclerest_data_services12.1.0.2cpe:2.3:a:oracle:rest_data_services:12.1.0.2:*:*:*:-:*:*:*
oraclerest_data_services12.2.0.1cpe:2.3:a:oracle:rest_data_services:12.2.0.1:*:*:*:-:*:*:*
Rows per page:
1-10 of 151

References

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.8

Confidence

High

EPSS

0.003

Percentile

69.6%