Information disclosure in Jetty - CVE-2017-7657

 

Information disclosure in Jetty - CVE-2017-7657

Published: July 2, 2018


Vulnerability identifier: #VU13528
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7657
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The vulnerability exists due to improper handling of queries that do not match the dynamic URL pattern for webapps that use default error handling settings. A remote attacker can send a query that submits malicious input, trigger a java.nio.file.InvalidPathException message, which could allow the attacker to view sensitive information, such as the software installation path.


Affected software

Jetty
IBM Business Automation Workflow
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Cloud Application Performance Management (APM)
IBM Spectrum Protect Storage Agent
IBM Security Verify Governance
Debian Linux
Fedora
Security Directory Integrator
Cloudera Observability with IBM
Dell Support Assist Enterprise
IBM Security Verify Directory
IBM Enterprise Records
IBM Security Directory Suite
CloudLink
BIG-IP
BIG-IQ Centralized Management
Cloudera Data Platform Private Cloud Base for IBM
Fuse
jetty
IBM Cognos Command Center

How to mitigate CVE-2017-7657

The vulnerability is addressed in the versions 9.3.24.v20180605 and 9.4.11.v20180605.

Jetty - addressed in versions 9.3.24.v20180605, 9.4.11.v20180605
Dell Support Assist Enterprise - update to 4.00.06.00
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.29
IBM Enterprise Records - update to 5.2.1.8 IF002
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.7 SP2 Cumulative Hotfix 16
Fuse - update to 7.3.0
IBM Security Directory Suite - update to 8.0.1.21
CloudLink - update to 8.0-3.10.5.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Spectrum Protect Storage Agent - update to 8.1.19
jetty - addressed in versions 9.4.11-2.v20180605.fc27, 9.4.11-2.v20180605.fc28
IBM Security Verify Governance - update to 10.0.1.0.3
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17

External References

Related Security Bulletins