CVE-2019-10247
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on jetty-distribution and jetty-home will include at the end of the Handler tree a DefaultHandler, which is responsible for reporting this 404 error, it presents the various configured contexts as HTML for users to click through to. This produced HTML includes output that contains the configured fully qualified directory base resource location for each context.
Affected (335)
Products: Eclipse: Jetty · Netapp: Element, Oncommand System Manager, Snap Creator Framework, Snapcenter, Snapmanager, Storage Replication Adapter For Clustered Data Ontap, Storage Services Connector, Vasa Provider For Clustered Data Ontap, Virtual Storage Console · Oracle: Autovue, Communications Analytics, Communications Element Manager, Communications Services Gatekeeper, Communications Session Report Manager, Communications Session Route Manager, Data Integrator, Endeca Information Discovery Integrator, Enterprise Manager Base Platform, Flexcube Core Banking, Flexcube Private Banking, Fmw Platform, Hospitality Guest Access, Retail Xstore Point Of Service, Unified Directory · +1 more
Show all products
Eclipse: Jetty · Netapp: Element, Oncommand System Manager, Snap Creator Framework, Snapcenter, Snapmanager, Storage Replication Adapter For Clustered Data Ontap, Storage Services Connector, Vasa Provider For Clustered Data Ontap, Virtual Storage Console · Oracle: Autovue, Communications Analytics, Communications Element Manager, Communications Services Gatekeeper, Communications Session Report Manager, Communications Session Route Manager, Data Integrator, Endeca Information Discovery Integrator, Enterprise Manager Base Platform, Flexcube Core Banking, Flexcube Private Banking, Fmw Platform, Hospitality Guest Access, Retail Xstore Point Of Service, Unified Directory · Debian: Debian Linux
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| From 3.0 to 3.1.3 | |
| All versions | |
| All versions | |
| All versions | |
| From 9.6 | |
| All versions | |
| From 9.6 | |
| From 9.6 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 21.0.2 | |
| Version 12.1.1 | |
| Version 8.0.0 | |
| Version 6.0 | |
| Version 8.0.0 | |
| Version 8.0.0 | |
| Version 12.2.1.3.0 | |
| Version 3.2.0 | |
| Version 13.2 | |
| From 11.5.0 to 11.7.0 | |
| Version 12.0.0 | |
| Version 12.2.1.3.0 | |
| Version 4.2.0 | |
| Version 15.0 | |
| Version 12.2.1.3.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Related CWEs
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-213
Exposure of Sensitive Information Due to Incompatible Policies
The product's intended functionality exposes information to certain actors in accordance with the developer's security policy, but this information is regarded as sensitive according to the intended security policies of other stakeholders such as the product's administrator, users, or others whose information is being processed.
References (36)
Source: emo@eclipse.org
Issue TrackingVendor Advisory
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Mailing ListThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.