CVE-2017-9735

Aliases:GHSA-wfcc-pff6-rgc5
Modified
Published: 16 Jun 2017, 21:00
Last modified:05 Aug 2024, 17:18

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.84% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Jun 2017, 21:00
Published
Vulnerability first disclosed
05 Aug 2024, 17:18
Last Modified
Vulnerability information updated

Description

Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.84% Percentile: 75%

Techniques & Countermeasures

  • CWE-203Observable Discrepancy

    The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Affected Systems

  • debiandebian_linux

    9.0

  • eclipsejetty

    < 9.2.22 | ≥ 9.3.0, < 9.3.20 | ≥ 9.4.0, < 9.4.6

  • org.eclipse.jettyjetty-server

    ≥ 9.4.0, < 9.4.6.v20170531 | ≥ 9.3.0, < 9.3.20.v20170531 | < 9.2.22.v20170606

  • oraclecommunications_cloud_native_core_policy

    1.5.0

  • oracleenterprise_manager_base_platform

    13.2 | 13.3

  • oraclehospitality_guest_access

    4.2.0 | 4.2.1

  • oraclerest_data_services

    11.2.0.4 | 12.1.0.2 | 12.2.0.1 | 18c

  • oracleretail_xstore_point_of_service

    7.1 | 15.0 | 16.0 | 17.0

References (23)