CVE-2017-9735

Aliases:GHSA-wfcc-pff6-rgc5DEBIAN-CVE-2017-9735CGA-67r9-98rp-qvc8CGA-hcm5-ww9m-578vCGA-j4vx-8m2g-j37gCGA-j8g4-cj46-788cCGA-jmwp-44cw-7276CGA-jrr4-fq39-2659CGA-pv99-m9x6-2pgqCGA-qw76-rq55-hhp9CGA-v74j-qm6c-6x26CGA-vw8r-q5v5-xhr6CGA-w9pq-ff7h-v9ppCGA-wj2x-hfwp-6fhrCGA-x4c7-9qq8-v82wCGA-xx6f-5p83-8r49
Modified
Published: 16 Jun 2017, 21:00
Last modified:05 Aug 2024, 17:18

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
5.79% LOW
6% probability +4.95%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Jun 2017, 21:00
Published
Vulnerability first disclosed
05 Aug 2024, 17:18
Last Modified
Vulnerability information updated

Description

Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 5.79% Percentile: 93%

Techniques & Countermeasures

  • CWE-203Observable Discrepancy

    The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Affected Systems

  • chainguardhadoop-fips-3.3.6

    all

  • chainguardhadoop-fips-3.4.2

    all

  • chainguardhadoop-fips-3.5

    all

  • debianjetty9

    < 9.2.22-1 | < 9.2.22-1 | < 9.2.22-1 | < 9.2.22-1

  • debiandebian_linux

    9.0

  • eclipsejetty

    < 9.2.22 | ≥ 9.3.0, < 9.3.20 | ≥ 9.4.0, < 9.4.6

  • org.eclipse.jettyjetty-server

    ≥ 9.4.0, < 9.4.6.v20170531 | ≥ 9.3.0, < 9.3.20.v20170531 | < 9.2.22.v20170606

  • oraclecommunications_cloud_native_core_policy

    1.5.0

  • oracleenterprise_manager_base_platform

    13.2 | 13.3

  • oraclehospitality_guest_access

    4.2.0 | 4.2.1

  • oraclerest_data_services

    11.2.0.4 | 12.1.0.2 | 12.2.0.1 | 18c

  • oracleretail_xstore_point_of_service

    7.1 | 15.0 | 16.0 | 17.0

References (24)