CVE-2019-10246

MEDIUMCVSS 5.3/10EPSS 4.02%

Last modified

CVE-2019-10246 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.. EPSS estimates a 4.02% chance of exploitation in the next 30 days.

Description

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS Probability
4.02%

89.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
EclipseJetty9.2.2720190403
EclipseJetty9.3.2620190403
EclipseJetty9.4.1620190411
NetappOncommand System Manager>= 3.0, <= 3.1.3
NetappSnap Creator FrameworkAll versions
NetappSnapcenterAll versions
NetappSnapmanagerAll versions
NetappStorage Replication Adapter For Clustered Data Ontap>= 9.6
NetappStorage Replication Adapter For Clustered Data Ontap9.6
NetappStorage Services ConnectorAll versions
NetappVasa Provider For Clustered Data Ontap>= 9.6
NetappVasa Provider For Clustered Data OntapAll versions
NetappVirtual Storage Console>= 9.6
NetappVirtual Storage Console9.6
NetappElementAll versions
OracleAutovue21.0.2
OracleCommunications Analytics12.1.1
OracleCommunications Element Manager8.0.0
OracleCommunications Element Manager8.1.0
OracleCommunications Element Manager8.1.1
OracleCommunications Element Manager8.2.0
OracleCommunications Services Gatekeeper6.0
OracleCommunications Services Gatekeeper6.1
OracleCommunications Services Gatekeeper7.0
OracleCommunications Session Report Manager8.0.0
OracleCommunications Session Report Manager8.1.0
OracleCommunications Session Report Manager8.1.1
OracleCommunications Session Report Manager8.2.0
OracleCommunications Session Route Manager8.0.0
OracleCommunications Session Route Manager8.1.0
OracleCommunications Session Route Manager8.1.1
OracleCommunications Session Route Manager8.2.0
OracleData Integrator12.2.1.3.0
OracleData Integrator12.2.1.4.0
OracleEndeca Information Discovery Integrator3.2.0
OracleEnterprise Manager Base Platform13.2
OracleEnterprise Manager Base Platform13.3
OracleFlexcube Core Banking>= 11.5.0, <= 11.7.0
OracleFlexcube Core Banking5.2.0
OracleFlexcube Private Banking12.0.0
OracleFlexcube Private Banking12.1.0
OracleHospitality Guest Access4.2.0
OracleHospitality Guest Access4.2.1
OracleRest Data Services11.2.0.4
OracleRest Data Services12.1.0.2
OracleRest Data Services12.2.0.1
OracleRest Data Services18c
OracleRetail Xstore Point Of Service7.1
OracleRetail Xstore Point Of Service15.0
OracleRetail Xstore Point Of Service16.0

Showing 50 of 53 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-10246?
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.
How severe is CVE-2019-10246?
CVE-2019-10246 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 4.02% probability of exploitation in the next 30 days.
How do I fix CVE-2019-10246?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-10246?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST