Information disclosure in Jetty - CVE-2018-12536

 

Information disclosure in Jetty - CVE-2018-12536

Published: July 2, 2018


Vulnerability identifier: #VU13530
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12536
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The vulnerability exists due to improper handling of queries that do not match the dynamic URL pattern for webapps that use default error handling settings. A remote attacker can send a query that submits malicious input, trigger a java.nio.file.InvalidPathException message, which could allow the attacker to view sensitive information, such as the software installation path.


Affected software

Jetty
BIG-IP
Cloudera Observability with IBM
BIG-IQ Centralized Management
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Cloud Application Performance Management (APM)
IBM Spectrum Protect Storage Agent
Fedora
Operational Decision Manager
jetty
IBM Cognos Command Center

How to mitigate CVE-2018-12536

The vulnerability is addressed in the versions 9.3.24.v20180605 and 9.4.11.v20180605.

Jetty - addressed in versions 9.3.24.v20180605, 9.4.11.v20180605
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.29
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
IBM Spectrum Protect Storage Agent - update to 8.1.19
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
jetty - addressed in versions 9.4.11-2.v20180605.fc27, 9.4.11-2.v20180605.fc28
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17

External References

Related Security Bulletins