← Back

CVE-2019-10246

nvd nist
Published: Apr 22, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

Affected (54)

1 product
Jetty
9 products
Element
Oncommand System Manager
Snap Creator Framework
Snapcenter
Snapmanager
Storage Services Connector
Virtual Storage Console
15 products
Autovue
Communications Analytics
Communications Element Manager
Data Integrator
Enterprise Manager Base Platform
Flexcube Core Banking
Flexcube Private Banking
Hospitality Guest Access
Rest Data Services
Retail Xstore Point Of Service
Unified Directory
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Eclipse
Version 9.2.27 20190403
Version 9.3.26 20190403
Version 9.4.16 20190411
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration B
13 vulnerable
Configuration C
38 vulnerable
Vulnerable SoftwareAffected Versions
Version 21.0.2
Version 12.1.1
Oracle
Version 8.0.0
Version 8.1.0
Version 8.1.1
Version 8.2.0
Oracle
Version 6.0
Version 6.1
Version 7.0
Oracle
Version 8.0.0
Version 8.1.0
Version 8.1.1
Version 8.2.0
Oracle
Version 8.0.0
Version 8.1.0
Version 8.1.1
Version 8.2.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 3.2.0
Oracle
Version 13.2
Version 13.3
Oracle
From 11.5.0 to 11.7.0
Version 5.2.0
Oracle
Version 12.0.0
Version 12.1.0
Oracle
Version 4.2.0
Version 4.2.1
Oracle
Version 11.2.0.4
Version 12.1.0.2
Version 12.2.0.1
Version 18c
Oracle
Version 15.0
Version 16.0
Version 17.0
Version 7.1
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0

References (22)

Source: emo@eclipse.org
Issue TrackingVendor Advisory
Source: emo@eclipse.org
Third Party Advisory
Source: emo@eclipse.org
Third Party Advisory
Source: emo@eclipse.org
Third Party Advisory
Source: emo@eclipse.org
Third Party Advisory
Source: emo@eclipse.org
Third Party Advisory
Source: emo@eclipse.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.