SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-10246

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory…

MEDIUM 5.3EPSS 4.02%

Does this matter?

Lower severity and a low EPSS score (4.02%). Track it; it rarely justifies an emergency change on its own.

Description

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
4.02% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-213, CWE-200
Affected
eclipse/jetty · netapp/oncommand system manager · netapp/snap creator framework · netapp/snapcenter · netapp/snapmanager · netapp/storage replication adapter for clustered data ontap · netapp/storage services connector · netapp/vasa provider for clustered data ontap · netapp/virtual storage console · netapp/element · oracle/autovue · oracle/communications analytics · oracle/communications element manager · oracle/communications services gatekeeper · oracle/communications session report manager · oracle/communications session route manager · oracle/data integrator · oracle/endeca information discovery integrator · oracle/enterprise manager base platform · oracle/flexcube core banking · +5 more
Source
emo@eclipse.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.