5.3

CVE-2019-10246

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

Data is provided by the National Vulnerability Database (NVD)
EclipseJetty Version9.2.27 Update20190403
   MicrosoftWindows Version-
EclipseJetty Version9.3.26 Update20190403
   MicrosoftWindows Version-
EclipseJetty Version9.4.16 Update20190411
   MicrosoftWindows Version-
NetappOncommand System Manager Version >= 3.0 <= 3.1.3
NetappSnapcenter Version-
NetappSnapmanager Version- Update- SwPlatformoracle
NetappSnapmanager Version- Update- SwPlatformsap
NetappStorage Replication Adapter For Clustered Data Ontap SwPlatformvmware_vsphere Version >= 9.6
NetappVirtual Storage Console SwPlatformvmware_vsphere Version >= 9.6
NetappElement Version- SwPlatformvcenter_server
OracleAutovue Version21.0.2
OracleCommunications Analytics Version12.1.1
OracleData Integrator Version12.2.1.3.0
OracleData Integrator Version12.2.1.4.0
OracleFlexcube Core Banking Version >= 11.5.0 <= 11.7.0
OracleFlexcube Core Banking Version5.2.0
OracleFlexcube Private Banking Version12.0.0
OracleFlexcube Private Banking Version12.1.0
OracleHospitality Guest Access Version4.2.0
OracleHospitality Guest Access Version4.2.1
OracleRest Data Services Version11.2.0.4 SwEdition-
OracleRest Data Services Version12.1.0.2 SwEdition-
OracleRest Data Services Version12.2.0.1 SwEdition-
OracleRest Data Services Version18c SwEdition-
OracleUnified Directory Version12.2.1.3.0
OracleUnified Directory Version12.2.1.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.7% 0.817
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-213 Exposure of Sensitive Information Due to Incompatible Policies

The product's intended functionality exposes information to certain actors in accordance with the developer's security policy, but this information is regarded as sensitive according to the intended security policies of other stakeholders such as the product's administrator, users, or others whose information is being processed.