ZeroHour

CVE-2017-9735

CVSS 3.1
7.5 high
EPSS
6%p93
Published
()
Modified
Description

Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

Vendors
eclipsedebianoracle
Products
jetty, debian linux, communications cloud native core policy, enterprise manager base platform, hospitality guest access, rest data services, retail xstore point of service
Weakness
CWE-203
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.