cbcvebase.
CVE-2019-10246
published 2019-04-22

CVE-2019-10246: In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory…

medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
debianjetty9
eclipsejetty
eclipsejetty
eclipsejetty
netapponcommand_system_manager3.0 – 3.1.3
netappstorage_replication_adapter_for_clustered_data_ontap
netappstorage_replication_adapter_for_clustered_data_ontap>= 9.6
netappvasa_provider_for_clustered_data_ontap>= 9.6
netappvirtual_storage_console
netappvirtual_storage_console>= 9.6
oracleautovue
oraclecommunications_analytics
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_services_gatekeeper
oraclecommunications_services_gatekeeper
oraclecommunications_services_gatekeeper
oraclecommunications_session_report_manager
oraclecommunications_session_report_manager
oraclecommunications_session_report_manager
oraclecommunications_session_report_manager
oraclecommunications_session_route_manager
oraclecommunications_session_route_manager