5.3
CVE-2019-10247
- EPSS 5.78%
- Veröffentlicht 22.04.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:44
- Erkennungen
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on jetty-distribution and jetty-home will include at the end of the Handler tree a DefaultHandler, which is responsible for reporting this 404 error, it presents the various configured contexts as HTML for users to click through to. This produced HTML includes output that contains the configured fully qualified directory base resource location for each context.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netapp ≫ Oncommand System Manager Version >= 3.0 <= 3.1.3
Netapp ≫ Snap Creator Framework Version -
Netapp ≫ Snapcenter Version -
Netapp ≫ Snapmanager Version - Update - SwPlatform oracle
Netapp ≫ Snapmanager Version - Update - SwPlatform sap
Netapp ≫ Storage Replication Adapter For Clustered Data Ontap SwPlatform vmware_vsphere Version >= 9.6
Netapp ≫ Storage Services Connector Version -
Netapp ≫ Vasa Provider For Clustered Data Ontap Version >= 9.6
Netapp ≫ Virtual Storage Console SwPlatform vmware_vsphere Version >= 9.6
Oracle ≫ Communications Analytics Version 12.1.1
Oracle ≫ Communications Element Manager Version 8.0.0
Oracle ≫ Communications Element Manager Version 8.1.0
Oracle ≫ Communications Element Manager Version 8.1.1
Oracle ≫ Communications Element Manager Version 8.2.0
Oracle ≫ Communications Services Gatekeeper Version 6.0
Oracle ≫ Communications Services Gatekeeper Version 6.1
Oracle ≫ Communications Services Gatekeeper Version 7.0
Oracle ≫ Communications Session Report Manager Version 8.0.0
Oracle ≫ Communications Session Report Manager Version 8.1.0
Oracle ≫ Communications Session Report Manager Version 8.1.1
Oracle ≫ Communications Session Report Manager Version 8.2.0
Oracle ≫ Communications Session Route Manager Version 8.0.0
Oracle ≫ Communications Session Route Manager Version 8.1.0
Oracle ≫ Communications Session Route Manager Version 8.1.1
Oracle ≫ Communications Session Route Manager Version 8.2.0
Oracle ≫ Data Integrator Version 12.2.1.3.0
Oracle ≫ Data Integrator Version 12.2.1.4.0
Oracle ≫ Endeca Information Discovery Integrator Version 3.2.0
Oracle ≫ Enterprise Manager Base Platform Version 13.2
Oracle ≫ Enterprise Manager Base Platform Version 13.3
Oracle ≫ Flexcube Core Banking Version >= 11.5.0 <= 11.7.0
Oracle ≫ Flexcube Core Banking Version 5.2.0
Oracle ≫ Flexcube Private Banking Version 12.0.0
Oracle ≫ Flexcube Private Banking Version 12.1.0
Oracle ≫ Fmw Platform Version 12.2.1.3.0
Oracle ≫ Fmw Platform Version 12.2.1.4.0
Oracle ≫ Hospitality Guest Access Version 4.2.0
Oracle ≫ Hospitality Guest Access Version 4.2.1
Oracle ≫ Retail Xstore Point Of Service Version 7.1
Oracle ≫ Retail Xstore Point Of Service Version 15.0
Oracle ≫ Retail Xstore Point Of Service Version 16.0
Oracle ≫ Retail Xstore Point Of Service Version 17.0
Oracle ≫ Unified Directory Version 12.2.1.3.0
Oracle ≫ Unified Directory Version 12.2.1.4.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.78% | 0.921 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-213 Exposure of Sensitive Information Due to Incompatible Policies
The product's intended functionality exposes information to certain actors in accordance with the developer's security policy, but this information is regarded as sensitive according to the intended security policies of other stakeholders such as the product's administrator, users, or others whose information is being processed.
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E
https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E
https://lists.apache.org/thread.html/ac51944aef91dd5006b8510b0bef337adaccfe962fb90e7af9c22db4%40%3Cissues.activemq.apache.org%3E
https://lists.debian.org/debian-lts-announce/2021/05/msg00016.html
https://security.netapp.com/advisory/ntap-20190509-0003/
https://www.debian.org/security/2021/dsa-4949
https://bugs.eclipse.org/bugs/show_bug.cgi?id=546577