cbcvebase.
CVE-2017-9735
published 2017-06-16

CVE-2017-9735: Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing…

PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
5.79%
92.3th percentile
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

Affected

19 ranges
VendorProductVersion rangeFixed in
atlassianjira_software
debiandebian_linux
debianjetty9< jetty9 9.2.22-1 (bookworm)jetty9 9.2.22-1 (bookworm)
eclipsejetty< 9.2.229.2.22
eclipsejetty>= 9.3.0 < 9.3.209.3.20
eclipsejetty>= 9.4.0 < 9.4.69.4.6
oraclecommunications_cloud_native_core_policy
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oraclehospitality_guest_access
oraclehospitality_guest_access
oraclerest_data_services
oraclerest_data_services
oraclerest_data_services
oraclerest_data_services
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.