5.3
CVE-2019-10246
- EPSS 4.02%
- Veröffentlicht 22.04.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:44
- Erkennungen
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netapp ≫ Oncommand System Manager Version >= 3.0 <= 3.1.3
Netapp ≫ Snap Creator Framework Version -
Netapp ≫ Snapcenter Version -
Netapp ≫ Snapmanager Version - Update - SwPlatform oracle
Netapp ≫ Snapmanager Version - Update - SwPlatform sap
Netapp ≫ Storage Replication Adapter For Clustered Data Ontap SwPlatform vmware_vsphere Version >= 9.6
Netapp ≫ Storage Replication Adapter For Clustered Data Ontap Version 9.6
Netapp ≫ Storage Services Connector Version -
Netapp ≫ Vasa Provider For Clustered Data Ontap Version >= 9.6
Netapp ≫ Vasa Provider For Clustered Data Ontap Version -
Netapp ≫ Virtual Storage Console SwPlatform vmware_vsphere Version >= 9.6
Netapp ≫ Virtual Storage Console Version 9.6
Oracle ≫ Communications Analytics Version 12.1.1
Oracle ≫ Communications Element Manager Version 8.0.0
Oracle ≫ Communications Element Manager Version 8.1.0
Oracle ≫ Communications Element Manager Version 8.1.1
Oracle ≫ Communications Element Manager Version 8.2.0
Oracle ≫ Communications Services Gatekeeper Version 6.0
Oracle ≫ Communications Services Gatekeeper Version 6.1
Oracle ≫ Communications Services Gatekeeper Version 7.0
Oracle ≫ Communications Session Report Manager Version 8.0.0
Oracle ≫ Communications Session Report Manager Version 8.1.0
Oracle ≫ Communications Session Report Manager Version 8.1.1
Oracle ≫ Communications Session Report Manager Version 8.2.0
Oracle ≫ Communications Session Route Manager Version 8.0.0
Oracle ≫ Communications Session Route Manager Version 8.1.0
Oracle ≫ Communications Session Route Manager Version 8.1.1
Oracle ≫ Communications Session Route Manager Version 8.2.0
Oracle ≫ Data Integrator Version 12.2.1.3.0
Oracle ≫ Data Integrator Version 12.2.1.4.0
Oracle ≫ Endeca Information Discovery Integrator Version 3.2.0
Oracle ≫ Enterprise Manager Base Platform Version 13.2
Oracle ≫ Enterprise Manager Base Platform Version 13.3
Oracle ≫ Flexcube Core Banking Version >= 11.5.0 <= 11.7.0
Oracle ≫ Flexcube Core Banking Version 5.2.0
Oracle ≫ Flexcube Private Banking Version 12.0.0
Oracle ≫ Flexcube Private Banking Version 12.1.0
Oracle ≫ Hospitality Guest Access Version 4.2.0
Oracle ≫ Hospitality Guest Access Version 4.2.1
Oracle ≫ Rest Data Services Version 11.2.0.4 SwEdition -
Oracle ≫ Rest Data Services Version 12.1.0.2 SwEdition -
Oracle ≫ Rest Data Services Version 12.2.0.1 SwEdition -
Oracle ≫ Rest Data Services Version 18c SwEdition -
Oracle ≫ Retail Xstore Point Of Service Version 7.1
Oracle ≫ Retail Xstore Point Of Service Version 15.0
Oracle ≫ Retail Xstore Point Of Service Version 16.0
Oracle ≫ Retail Xstore Point Of Service Version 17.0
Oracle ≫ Unified Directory Version 12.2.1.3.0
Oracle ≫ Unified Directory Version 12.2.1.4.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.02% | 0.892 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-213 Exposure of Sensitive Information Due to Incompatible Policies
The product's intended functionality exposes information to certain actors in accordance with the developer's security policy, but this information is regarded as sensitive according to the intended security policies of other stakeholders such as the product's administrator, users, or others whose information is being processed.
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E
https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E
https://security.netapp.com/advisory/ntap-20190509-0003/
https://bugs.eclipse.org/bugs/show_bug.cgi?id=546576