9.8

CVE-2016-4800

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

Data is provided by the National Vulnerability Database (NVD)
EclipseJetty Version9.3.0
   MicrosoftWindows
EclipseJetty Version9.3.0 Updatem0
   MicrosoftWindows
EclipseJetty Version9.3.0 Updatem1
   MicrosoftWindows
EclipseJetty Version9.3.0 Updatemaintenance2
   MicrosoftWindows
EclipseJetty Version9.3.0 Updaterc0
   MicrosoftWindows
EclipseJetty Version9.3.0 Updaterc1
   MicrosoftWindows
EclipseJetty Version9.3.1
   MicrosoftWindows
EclipseJetty Version9.3.2
   MicrosoftWindows
EclipseJetty Version9.3.3
   MicrosoftWindows
EclipseJetty Version9.3.4
   MicrosoftWindows
EclipseJetty Version9.3.4 Updaterc0
   MicrosoftWindows
EclipseJetty Version9.3.4 Updaterc1
   MicrosoftWindows
EclipseJetty Version9.3.5
   MicrosoftWindows
EclipseJetty Version9.3.6
   MicrosoftWindows
EclipseJetty Version9.3.7
   MicrosoftWindows
EclipseJetty Version9.3.7 Updaterc0
   MicrosoftWindows
EclipseJetty Version9.3.7 Updaterc1
   MicrosoftWindows
EclipseJetty Version9.3.8
   MicrosoftWindows
EclipseJetty Version9.3.8 Updaterc0
   MicrosoftWindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.64% 0.697
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.