CVE-2019-10246
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.
Affected (54)
Products: Eclipse: Jetty · Netapp: Element, Oncommand System Manager, Snap Creator Framework, Snapcenter, Snapmanager, Storage Replication Adapter For Clustered Data Ontap, Storage Services Connector, Vasa Provider For Clustered Data Ontap, Virtual Storage Console · Oracle: Autovue, Communications Analytics, Communications Element Manager, Communications Services Gatekeeper, Communications Session Report Manager, Communications Session Route Manager, Data Integrator, Endeca Information Discovery Integrator, Enterprise Manager Base Platform, Flexcube Core Banking, Flexcube Private Banking, Hospitality Guest Access, Rest Data Services, Retail Xstore Point Of Service, Unified Directory
Configuration A
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| From 3.0 to 3.1.3 | |
| All versions | |
| All versions | |
| All versions | |
| From 9.6 | |
| All versions | |
| From 9.6 | |
| From 9.6 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 21.0.2 | |
| Version 12.1.1 | |
| Version 8.0.0 | |
| Version 6.0 | |
| Version 8.0.0 | |
| Version 8.0.0 | |
| Version 12.2.1.3.0 | |
| Version 3.2.0 | |
| Version 13.2 | |
| From 11.5.0 to 11.7.0 | |
| Version 12.0.0 | |
| Version 4.2.0 | |
| Version 11.2.0.4 | |
| Version 15.0 | |
| Version 12.2.1.3.0 |
Related CWEs
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-213
Exposure of Sensitive Information Due to Incompatible Policies
The product's intended functionality exposes information to certain actors in accordance with the developer's security policy, but this information is regarded as sensitive according to the intended security policies of other stakeholders such as the product's administrator, users, or others whose information is being processed.
References (22)
Source: emo@eclipse.org
Issue TrackingVendor Advisory
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.