CVE-2021-28164
01.04.2021, 15:15
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.Enginsight
Vendor | Product | Version |
---|---|---|
eclipse | jetty | 9.4.37:20210219 |
eclipse | jetty | 9.4.38:20210224 |
netapp | cloud_manager | - |
netapp | e-series_performance_analyzer | - |
netapp | e-series_santricity_os_controller | 11.0 ≤ 𝑥 ≤ 11.70.1 |
netapp | e-series_santricity_web_services | - |
netapp | element_plug-in_for_vcenter_server | - |
netapp | santricity_cloud_connector | - |
netapp | snapcenter | - |
netapp | snapcenter_plug-in | - |
netapp | storage_replication_adapter_for_clustered_data_ontap | 9.6 ≤ |
netapp | vasa_provider_for_clustered_data_ontap | 9.6 ≤ |
netapp | virtual_storage_console | 9.6 ≤ |
oracle | autovue_for_agile_product_lifecycle_management | 21.0.2 |
oracle | banking_apis | 20.1 |
oracle | banking_apis | 21.1 |
oracle | banking_digital_experience | 20.1 |
oracle | banking_digital_experience | 21.1 |
oracle | communications_session_route_manager | 8.0.0 ≤ 𝑥 ≤ 8.2.4 |
oracle | siebel_core_-_automation | 𝑥 ≤ 21.9 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References