CVE-2017-9735
Summary
| CVE | CVE-2017-9735 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-16 21:29:00 UTC |
| Updated | 2023-11-07 02:50:00 UTC |
| Description | Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords. |
Risk And Classification
Problem Types: CWE-203
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Eclipse | Jetty | All | All | All | All |
| Application | Eclipse | Jetty | All | 20170531 | All | All |
| Application | Oracle | Communications Cloud Native Core Policy | 1.5.0 | All | All | All |
| Application | Oracle | Enterprise Manager Base Platform | 13.2 | All | All | All |
| Application | Oracle | Enterprise Manager Base Platform | 13.3 | All | All | All |
| Application | Oracle | Hospitality Guest Access | 4.2.0 | All | All | All |
| Application | Oracle | Hospitality Guest Access | 4.2.1 | All | All | All |
| Application | Oracle | Rest Data Services | 11.2.0.4 | All | All | All |
| Application | Oracle | Rest Data Services | 12.1.0.2 | All | All | All |
| Application | Oracle | Rest Data Services | 12.2.0.1 | All | All | All |
| Application | Oracle | Rest Data Services | 18c | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 15.0 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 16.0 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 17.0 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 7.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | lists.apache.org | ||
| [SECURITY] [DLA 2661-1] jetty9 security update | MLIST | lists.debian.org | |
| #864631 - unblock: jetty9/9.2.22-1 - Debian Bug report logs | MISC | bugs.debian.org | Mailing List, Third Party Advisory |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Oracle Critical Patch Update Advisory - October 2020 | MISC | www.oracle.com | |
| Oracle Critical Patch Update Advisory - July 2021 | N/A | www.oracle.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Remove a timing channel in Password matching · Issue #1556 · eclipse/jetty.project · GitHub | MISC | github.com | Third Party Advisory |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Oracle Critical Patch Update - October 2019 | MISC | www.oracle.com | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.