CVE-2019-10247
22.04.2019, 20:29
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on jetty-distribution and jetty-home will include at the end of the Handler tree a DefaultHandler, which is responsible for reporting this 404 error, it presents the various configured contexts as HTML for users to click through to. This produced HTML includes output that contains the configured fully qualified directory base resource location for each context.Enginsight
Vendor | Product | Version |
---|---|---|
eclipse | jetty | 7.0.0:20091005 |
eclipse | jetty | 7.0.0:maintenance_0 |
eclipse | jetty | 7.0.0:maintenance_1 |
eclipse | jetty | 7.0.0:maintenance_2 |
eclipse | jetty | 7.0.0:maintenance_3 |
eclipse | jetty | 7.0.0:maintenance_4 |
eclipse | jetty | 7.0.0:rc0 |
eclipse | jetty | 7.0.0:rc1 |
eclipse | jetty | 7.0.0:rc3 |
eclipse | jetty | 7.0.0:rc4 |
eclipse | jetty | 7.0.0:rc5 |
eclipse | jetty | 7.0.0:rc6 |
eclipse | jetty | 7.0.1:20091125 |
eclipse | jetty | 7.0.2:20100331 |
eclipse | jetty | 7.0.2:rc0 |
eclipse | jetty | 7.1.0:20100505 |
eclipse | jetty | 7.1.0:rc0 |
eclipse | jetty | 7.1.0:rc1 |
eclipse | jetty | 7.1.1:20100517 |
eclipse | jetty | 7.1.2:20100523 |
eclipse | jetty | 7.1.3:20100526 |
eclipse | jetty | 7.1.4:20100610 |
eclipse | jetty | 7.1.5:20100705 |
eclipse | jetty | 7.1.6:20100715 |
eclipse | jetty | 7.2.0:20101020 |
eclipse | jetty | 7.2.0:rc0 |
eclipse | jetty | 7.2.1:20101111 |
eclipse | jetty | 7.2.2:20101205 |
eclipse | jetty | 7.3.0:20110203 |
eclipse | jetty | 7.3.1:20110307 |
eclipse | jetty | 7.4.0:20110414 |
eclipse | jetty | 7.4.0:rc0 |
eclipse | jetty | 7.4.1:20110513 |
eclipse | jetty | 7.4.2:20110526 |
eclipse | jetty | 7.4.3:20110630 |
eclipse | jetty | 7.4.3:20110701 |
eclipse | jetty | 7.4.4:20110707 |
eclipse | jetty | 7.4.5:20110725 |
eclipse | jetty | 7.5.0:20110901 |
eclipse | jetty | 7.5.0:rc0 |
eclipse | jetty | 7.5.0:rc1 |
eclipse | jetty | 7.5.0:rc2 |
eclipse | jetty | 7.5.1:20110908 |
eclipse | jetty | 7.5.2:20111006 |
eclipse | jetty | 7.5.3:20111011 |
eclipse | jetty | 7.5.4:20111024 |
eclipse | jetty | 7.6.0:20120125 |
eclipse | jetty | 7.6.0:20120127 |
eclipse | jetty | 7.6.0:rc0 |
eclipse | jetty | 7.6.0:rc1 |
eclipse | jetty | 7.6.0:rc2 |
eclipse | jetty | 7.6.0:rc3 |
eclipse | jetty | 7.6.0:rc4 |
eclipse | jetty | 7.6.0:rc5 |
eclipse | jetty | 7.6.1:20120215 |
eclipse | jetty | 7.6.2:20120302 |
eclipse | jetty | 7.6.2:20120308 |
eclipse | jetty | 7.6.3:20120413 |
eclipse | jetty | 7.6.3:20120416 |
eclipse | jetty | 7.6.4:20120522 |
eclipse | jetty | 7.6.4:20120524 |
eclipse | jetty | 7.6.5:20120713 |
eclipse | jetty | 7.6.5:20120716 |
eclipse | jetty | 7.6.6:20120903 |
eclipse | jetty | 7.6.7:20120910 |
eclipse | jetty | 7.6.8:20121106 |
eclipse | jetty | 7.6.9:20130131 |
eclipse | jetty | 7.6.10:20130312 |
eclipse | jetty | 7.6.11:20130520 |
eclipse | jetty | 7.6.11:20130725 |
eclipse | jetty | 7.6.12:20130726 |
eclipse | jetty | 7.6.13:20130910 |
eclipse | jetty | 7.6.13:20130916 |
eclipse | jetty | 7.6.14:20131031 |
eclipse | jetty | 7.6.15:20140411 |
eclipse | jetty | 7.6.16:20140903 |
eclipse | jetty | 7.6.17:20150415 |
eclipse | jetty | 7.6.18:20150929 |
eclipse | jetty | 7.6.19:20160209 |
eclipse | jetty | 7.6.20:20160902 |
eclipse | jetty | 7.6.21:20160908 |
eclipse | jetty | 8.0.0:20110901 |
eclipse | jetty | 8.0.0:maintenance_0 |
eclipse | jetty | 8.0.0:maintenance_1 |
eclipse | jetty | 8.0.0:maintenance_2 |
eclipse | jetty | 8.0.0:maintenance_3 |
eclipse | jetty | 8.0.0:rc0 |
eclipse | jetty | 8.0.1:20110908 |
eclipse | jetty | 8.0.2:20111006 |
eclipse | jetty | 8.0.3:20111011 |
eclipse | jetty | 8.0.4:20111024 |
eclipse | jetty | 8.1.0:20120127 |
eclipse | jetty | 8.1.0:rc0 |
eclipse | jetty | 8.1.0:rc1 |
eclipse | jetty | 8.1.0:rc2 |
eclipse | jetty | 8.1.0:rc4 |
eclipse | jetty | 8.1.0:rc5 |
eclipse | jetty | 8.1.1:20120215 |
eclipse | jetty | 8.1.2:20120302 |
eclipse | jetty | 8.1.2:20120308 |
eclipse | jetty | 8.1.3:20120416 |
eclipse | jetty | 8.1.4:20120524 |
eclipse | jetty | 8.1.5:20120713 |
eclipse | jetty | 8.1.5:20120716 |
eclipse | jetty | 8.1.6:20120903 |
eclipse | jetty | 8.1.7:20120910 |
eclipse | jetty | 8.1.8:20121106 |
eclipse | jetty | 8.1.9:20130131 |
eclipse | jetty | 8.1.10:20130312 |
eclipse | jetty | 8.1.11:20130520 |
eclipse | jetty | 8.1.12:20130725 |
eclipse | jetty | 8.1.12:20130726 |
eclipse | jetty | 8.1.13:20130910 |
eclipse | jetty | 8.1.13:20130916 |
eclipse | jetty | 8.1.14:20131031 |
eclipse | jetty | 8.1.15:20140411 |
eclipse | jetty | 8.1.16:20140903 |
eclipse | jetty | 8.1.17:20150415 |
eclipse | jetty | 8.1.18:20150929 |
eclipse | jetty | 8.1.19:20160209 |
eclipse | jetty | 8.1.20:20160902 |
eclipse | jetty | 8.1.21:20160908 |
eclipse | jetty | 8.1.22:20160922 |
eclipse | jetty | 8.2.0:20160908 |
eclipse | jetty | 9.0.0:20130308 |
eclipse | jetty | 9.0.0:m5 |
eclipse | jetty | 9.0.0:maintenance_0 |
eclipse | jetty | 9.0.0:maintenance_1 |
eclipse | jetty | 9.0.0:maintenance_2 |
eclipse | jetty | 9.0.0:maintenance_3 |
eclipse | jetty | 9.0.0:maintenance_4 |
eclipse | jetty | 9.0.0:maintenance_5 |
eclipse | jetty | 9.0.0:rc0 |
eclipse | jetty | 9.0.0:rc1 |
eclipse | jetty | 9.0.0:rc2 |
eclipse | jetty | 9.0.0:rc3 |
eclipse | jetty | 9.0.1:20130408 |
eclipse | jetty | 9.0.2:20130417 |
eclipse | jetty | 9.0.2:20140415 |
eclipse | jetty | 9.0.3:20130506 |
eclipse | jetty | 9.0.4:20130621 |
eclipse | jetty | 9.0.4:20130625 |
eclipse | jetty | 9.0.5:20130813 |
eclipse | jetty | 9.0.5:20130815 |
eclipse | jetty | 9.0.6:20130919 |
eclipse | jetty | 9.0.6:20130930 |
eclipse | jetty | 9.0.7:20131031 |
eclipse | jetty | 9.0.7:20131107 |
eclipse | jetty | 9.1.0:20131115 |
eclipse | jetty | 9.1.0:maintenance_0 |
eclipse | jetty | 9.1.0:rc0 |
eclipse | jetty | 9.1.0:rc1 |
eclipse | jetty | 9.1.0:rc2 |
eclipse | jetty | 9.1.1:20140108 |
eclipse | jetty | 9.1.2:20140210 |
eclipse | jetty | 9.1.3:20140225 |
eclipse | jetty | 9.1.4:20140401 |
eclipse | jetty | 9.1.5:20140505 |
eclipse | jetty | 9.1.6:20151106 |
eclipse | jetty | 9.1.6:20160112 |
eclipse | jetty | 9.2.0:20140523 |
eclipse | jetty | 9.2.0:20140526 |
eclipse | jetty | 9.2.0:maintenance_0 |
eclipse | jetty | 9.2.0:maintenance_1 |
eclipse | jetty | 9.2.0:rc0 |
eclipse | jetty | 9.2.1:20140609 |
eclipse | jetty | 9.2.2:20140723 |
eclipse | jetty | 9.2.3:20140905 |
eclipse | jetty | 9.2.4:20141103 |
eclipse | jetty | 9.2.5:20141112 |
eclipse | jetty | 9.2.6:20141203 |
eclipse | jetty | 9.2.6:20141205 |
eclipse | jetty | 9.2.7:20150116 |
eclipse | jetty | 9.2.8:20150217 |
eclipse | jetty | 9.2.9:20150224 |
eclipse | jetty | 9.2.10:20150310 |
eclipse | jetty | 9.2.11:20150528 |
eclipse | jetty | 9.2.11:20150529 |
eclipse | jetty | 9.2.11:maintenance_0 |
eclipse | jetty | 9.2.12:20150709 |
eclipse | jetty | 9.2.12:maintenance_0 |
eclipse | jetty | 9.2.13:20150730 |
eclipse | jetty | 9.2.14:20151106 |
eclipse | jetty | 9.2.15:20160210 |
eclipse | jetty | 9.2.16:20160407 |
eclipse | jetty | 9.2.16:20160414 |
eclipse | jetty | 9.2.17:20160517 |
eclipse | jetty | 9.2.18:20160721 |
eclipse | jetty | 9.2.19:20160908 |
eclipse | jetty | 9.2.20:20161216 |
eclipse | jetty | 9.2.21:20170120 |
eclipse | jetty | 9.2.22:20170606 |
eclipse | jetty | 9.2.23:20171218 |
eclipse | jetty | 9.2.24:20180105 |
eclipse | jetty | 9.2.25:20180606 |
eclipse | jetty | 9.2.26:20180806 |
eclipse | jetty | 9.2.27:20190403 |
eclipse | jetty | 9.3.0:20150601 |
eclipse | jetty | 9.3.0:20150608 |
eclipse | jetty | 9.3.0:20150612 |
eclipse | jetty | 9.3.0:maintenance0 |
eclipse | jetty | 9.3.0:maintenance1 |
eclipse | jetty | 9.3.0:maintenance2 |
eclipse | jetty | 9.3.0:rc0 |
eclipse | jetty | 9.3.0:rc1 |
eclipse | jetty | 9.3.1:20150714 |
eclipse | jetty | 9.3.2:20150730 |
eclipse | jetty | 9.3.3:20150825 |
eclipse | jetty | 9.3.3:20150827 |
eclipse | jetty | 9.3.4:20151005 |
eclipse | jetty | 9.3.4:20151007 |
eclipse | jetty | 9.3.4:rc0 |
eclipse | jetty | 9.3.4:rc1 |
eclipse | jetty | 9.3.5:20151012 |
eclipse | jetty | 9.3.6:20151106 |
eclipse | jetty | 9.3.7:20160115 |
eclipse | jetty | 9.3.7:rc0 |
eclipse | jetty | 9.3.7:rc1 |
eclipse | jetty | 9.3.8:20160311 |
eclipse | jetty | 9.3.8:20160314 |
eclipse | jetty | 9.3.8:rc0 |
eclipse | jetty | 9.3.9:20160517 |
eclipse | jetty | 9.3.9:maintenance_0 |
eclipse | jetty | 9.3.9:maintenance_1 |
eclipse | jetty | 9.3.10:20160621 |
eclipse | jetty | 9.3.10:maintenance_0 |
eclipse | jetty | 9.3.11:20160721 |
eclipse | jetty | 9.3.11:maintenance_0 |
eclipse | jetty | 9.3.12:20160915 |
eclipse | jetty | 9.3.13:20161014 |
eclipse | jetty | 9.3.13:maintenance_0 |
eclipse | jetty | 9.3.14:20161028 |
eclipse | jetty | 9.3.15:20161220 |
eclipse | jetty | 9.3.16:20170119 |
eclipse | jetty | 9.3.16:20170120 |
eclipse | jetty | 9.3.17:20170317 |
eclipse | jetty | 9.3.17:rc0 |
eclipse | jetty | 9.3.18:20170406 |
eclipse | jetty | 9.3.19:20170502 |
eclipse | jetty | 9.3.20:20170531 |
eclipse | jetty | 9.3.21:20170918 |
eclipse | jetty | 9.3.21:maintenance_0 |
eclipse | jetty | 9.3.21:rc0 |
eclipse | jetty | 9.3.22:20171030 |
eclipse | jetty | 9.3.23:20180228 |
eclipse | jetty | 9.3.24:20180605 |
eclipse | jetty | 9.3.25:20180904 |
eclipse | jetty | 9.3.26:20190403 |
eclipse | jetty | 9.4.0:20161207 |
eclipse | jetty | 9.4.0:20161208 |
eclipse | jetty | 9.4.0:20180619 |
eclipse | jetty | 9.4.0:maintenance_0 |
eclipse | jetty | 9.4.0:maintenance_1 |
eclipse | jetty | 9.4.0:rc0 |
eclipse | jetty | 9.4.0:rc1 |
eclipse | jetty | 9.4.0:rc2 |
eclipse | jetty | 9.4.0:rc3 |
eclipse | jetty | 9.4.1:20170120 |
eclipse | jetty | 9.4.1:20180619 |
eclipse | jetty | 9.4.2:20170220 |
eclipse | jetty | 9.4.2:20180619 |
eclipse | jetty | 9.4.3:20170317 |
eclipse | jetty | 9.4.3:20180619 |
eclipse | jetty | 9.4.4:20170410 |
eclipse | jetty | 9.4.4:20170414 |
eclipse | jetty | 9.4.4:20180619 |
eclipse | jetty | 9.4.5:20170502 |
eclipse | jetty | 9.4.5:20180619 |
eclipse | jetty | 9.4.6:20170531 |
eclipse | jetty | 9.4.6:20180619 |
eclipse | jetty | 9.4.7:20170914 |
eclipse | jetty | 9.4.7:20180619 |
eclipse | jetty | 9.4.7:rc0 |
eclipse | jetty | 9.4.8:20171121 |
eclipse | jetty | 9.4.8:20180619 |
eclipse | jetty | 9.4.9:20180320 |
eclipse | jetty | 9.4.10:20180503 |
eclipse | jetty | 9.4.10:rc0 |
eclipse | jetty | 9.4.10:rc1 |
eclipse | jetty | 9.4.11:20180605 |
eclipse | jetty | 9.4.12:20180830 |
eclipse | jetty | 9.4.12:rc0 |
eclipse | jetty | 9.4.12:rc1 |
eclipse | jetty | 9.4.12:rc2 |
eclipse | jetty | 9.4.13:20181111 |
eclipse | jetty | 9.4.14:20181114 |
eclipse | jetty | 9.4.15:20190215 |
netapp | oncommand_system_manager | 3.0 ≤ 𝑥 ≤ 3.1.3 |
netapp | snap_creator_framework | - |
netapp | snapcenter | - |
netapp | snapmanager | - |
netapp | snapmanager | - |
netapp | storage_replication_adapter_for_clustered_data_ontap | 9.6 ≤ |
netapp | storage_services_connector | - |
netapp | vasa_provider_for_clustered_data_ontap | 9.6 ≤ |
netapp | virtual_storage_console | 9.6 ≤ |
netapp | element | - |
oracle | autovue | 21.0.2 |
oracle | communications_analytics | 12.1.1 |
oracle | communications_element_manager | 8.0.0 |
oracle | communications_element_manager | 8.1.0 |
oracle | communications_element_manager | 8.1.1 |
oracle | communications_element_manager | 8.2.0 |
oracle | communications_services_gatekeeper | 6.0 |
oracle | communications_services_gatekeeper | 6.1 |
oracle | communications_services_gatekeeper | 7.0 |
oracle | communications_session_report_manager | 8.0.0 |
oracle | communications_session_report_manager | 8.1.0 |
oracle | communications_session_report_manager | 8.1.1 |
oracle | communications_session_report_manager | 8.2.0 |
oracle | communications_session_route_manager | 8.0.0 |
oracle | communications_session_route_manager | 8.1.0 |
oracle | communications_session_route_manager | 8.1.1 |
oracle | communications_session_route_manager | 8.2.0 |
oracle | data_integrator | 12.2.1.3.0 |
oracle | data_integrator | 12.2.1.4.0 |
oracle | endeca_information_discovery_integrator | 3.2.0 |
oracle | enterprise_manager_base_platform | 13.2 |
oracle | enterprise_manager_base_platform | 13.3 |
oracle | flexcube_core_banking | 11.5.0 ≤ 𝑥 ≤ 11.7.0 |
oracle | flexcube_core_banking | 5.2.0 |
oracle | flexcube_private_banking | 12.0.0 |
oracle | flexcube_private_banking | 12.1.0 |
oracle | fmw_platform | 12.2.1.3.0 |
oracle | fmw_platform | 12.2.1.4.0 |
oracle | hospitality_guest_access | 4.2.0 |
oracle | hospitality_guest_access | 4.2.1 |
oracle | retail_xstore_point_of_service | 7.1 |
oracle | retail_xstore_point_of_service | 15.0 |
oracle | retail_xstore_point_of_service | 16.0 |
oracle | retail_xstore_point_of_service | 17.0 |
oracle | unified_directory | 12.2.1.3.0 |
oracle | unified_directory | 12.2.1.4.0 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
jetty |
| ||||||||||||||||||||||||||||||
jetty8 |
| ||||||||||||||||||||||||||||||
jetty9 |
|
Common Weakness Enumeration
- CWE-213 - Exposure of Sensitive Information Due to Incompatible PoliciesThe product's intended functionality exposes information to certain actors in accordance with the developer's security policy, but this information is regarded as sensitive according to the intended security policies of other stakeholders such as the product's administrator, users, or others whose information is being processed.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
References