cbcvebase.
CVE-2019-10246
published 2019-04-22

CVE-2019-10246: In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory…

PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
4.02%
89.4th percentile
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
debianjetty9
eclipsejetty
eclipsejetty
eclipsejetty
netapponcommand_system_manager3.0 – 3.1.3
netappstorage_replication_adapter_for_clustered_data_ontap
netappstorage_replication_adapter_for_clustered_data_ontap>= 9.6
netappvasa_provider_for_clustered_data_ontap>= 9.6
netappvirtual_storage_console
netappvirtual_storage_console>= 9.6
oracleautovue
oraclecommunications_analytics
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_services_gatekeeper
oraclecommunications_services_gatekeeper
oraclecommunications_services_gatekeeper
oraclecommunications_session_report_manager
oraclecommunications_session_report_manager
oraclecommunications_session_report_manager
oraclecommunications_session_report_manager
oraclecommunications_session_route_manager
oraclecommunications_session_route_manager

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.