5.3

CVE-2019-10246

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eclipse ≫ Jetty Version 9.2.27 Update 20190403
   Microsoft ≫ Windows Version -
Eclipse ≫ Jetty Version 9.3.26 Update 20190403
   Microsoft ≫ Windows Version -
Eclipse ≫ Jetty Version 9.4.16 Update 20190411
   Microsoft ≫ Windows Version -
Netapp ≫ Oncommand System Manager Version >= 3.0 <= 3.1.3
Netapp ≫ Snapcenter Version -
Netapp ≫ Snapmanager Version - Update - SwPlatform oracle
Netapp ≫ Snapmanager Version - Update - SwPlatform sap
Netapp ≫ Storage Replication Adapter For Clustered Data Ontap SwPlatform vmware_vsphere Version >= 9.6
Netapp ≫ Virtual Storage Console SwPlatform vmware_vsphere Version >= 9.6
Netapp ≫ Element Version - SwPlatform vcenter_server
Oracle ≫ Autovue Version 21.0.2
Oracle ≫ Communications Analytics Version 12.1.1
Oracle ≫ Data Integrator Version 12.2.1.3.0
Oracle ≫ Data Integrator Version 12.2.1.4.0
Oracle ≫ Flexcube Core Banking Version >= 11.5.0 <= 11.7.0
Oracle ≫ Flexcube Core Banking Version 5.2.0
Oracle ≫ Flexcube Private Banking Version 12.0.0
Oracle ≫ Flexcube Private Banking Version 12.1.0
Oracle ≫ Hospitality Guest Access Version 4.2.0
Oracle ≫ Hospitality Guest Access Version 4.2.1
Oracle ≫ Rest Data Services Version 11.2.0.4 SwEdition -
Oracle ≫ Rest Data Services Version 12.1.0.2 SwEdition -
Oracle ≫ Rest Data Services Version 12.2.0.1 SwEdition -
Oracle ≫ Rest Data Services Version 18c SwEdition -
Oracle ≫ Unified Directory Version 12.2.1.3.0
Oracle ≫ Unified Directory Version 12.2.1.4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.02% 0.892
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-213 Exposure of Sensitive Information Due to Incompatible Policies

The product's intended functionality exposes information to certain actors in accordance with the developer's security policy, but this information is regarded as sensitive according to the intended security policies of other stakeholders such as the product's administrator, users, or others whose information is being processed.

https://www.oracle.com/security-alerts/cpujan2020.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Third Party Advisory
https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E
https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E
https://security.netapp.com/advisory/ntap-20190509-0003/
Third Party Advisory
https://bugs.eclipse.org/bugs/show_bug.cgi?id=546576
Vendor Advisory
Issue Tracking