Brute-force attack in Jetty - CVE-2017-9735
Published: June 17, 2017 / Updated: November 22, 2023
Vulnerability identifier: #VU9654
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9735
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a brute-force attack.
The vulnerability exists due to a timing channel in util/security/Password.java, which allows a remote attacker to perform a brute-force attack by observing elapsed times before rejection of incorrect passwords.
The vulnerability exists due to a timing channel in util/security/Password.java, which allows a remote attacker to perform a brute-force attack by observing elapsed times before rejection of incorrect passwords.
Affected software
Jetty
Security Directory Integrator
Cloudera Observability with IBM
Dell Support Assist Enterprise
IBM Security Verify Directory
IBM Security Directory Suite
CloudLink
Oracle Communications Cloud Native Core Policy
Crowd Server
Crowd Data Center
IBM Cloud Application Performance Management (APM)
Jira Software Data Center
IBM Spectrum Protect Storage Agent
Jira Software Server
Fedora
jetty-test-helper
jetty-alpn
jetty
Security Directory Integrator
Cloudera Observability with IBM
Dell Support Assist Enterprise
IBM Security Verify Directory
IBM Security Directory Suite
CloudLink
Oracle Communications Cloud Native Core Policy
Crowd Server
Crowd Data Center
IBM Cloud Application Performance Management (APM)
Jira Software Data Center
IBM Spectrum Protect Storage Agent
Jira Software Server
Fedora
jetty-test-helper
jetty-alpn
jetty
How to mitigate CVE-2017-9735
Update to version 9.4.6.v20170531, 9.3.20.v20170531 or
jetty-9.2.22.v20170606.
Dell Support Assist Enterprise - update to 4.00.06.00
Crowd Server - addressed in versions 5.0.11, 5.1.9, 5.2.4
Crowd Data Center - addressed in versions 5.0.11, 5.1.9, 5.2.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
Jira Software Data Center - addressed in versions 8.20.27, 9.10.2, 9.11.1
Jira Software Server - addressed in versions 8.20.27, 9.10.2, 9.11.1
jetty-test-helper - update to 3.1-3.fc25
IBM Security Directory Suite - update to 8.0.1.21
CloudLink - update to 8.0-3.10.5.1
jetty-alpn - update to 8.1.11-2.v20170118.fc25
IBM Spectrum Protect Storage Agent - update to 8.1.19
jetty - addressed in versions 9.3.7-3.v20160115.fc24, 9.4.6-1.v20170531.fc25, 9.4.6-1.v20170531.fc26
Crowd Server - addressed in versions 5.0.11, 5.1.9, 5.2.4
Crowd Data Center - addressed in versions 5.0.11, 5.1.9, 5.2.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
Jira Software Data Center - addressed in versions 8.20.27, 9.10.2, 9.11.1
Jira Software Server - addressed in versions 8.20.27, 9.10.2, 9.11.1
jetty-test-helper - update to 3.1-3.fc25
IBM Security Directory Suite - update to 8.0.1.21
CloudLink - update to 8.0-3.10.5.1
jetty-alpn - update to 8.1.11-2.v20170118.fc25
IBM Spectrum Protect Storage Agent - update to 8.1.19
jetty - addressed in versions 9.3.7-3.v20160115.fc24, 9.4.6-1.v20170531.fc25, 9.4.6-1.v20170531.fc26
External References
Related Security Bulletins
- Security restrictions bypass in Eclipse Jetty
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Dell CloudLink
- Multiple vulnerabilities in IBM Storage Protect Server
- Jira Software Data Center and Server update for Jetty
- Multiple vulnerabilities in IBM Security Directory Integrator
- Crowd Data Center and Server update for jetty-util
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Multiple vulnerabilities in IBM Security Verify Directory
- Multiple vulnerabilities in IBM Security Directory Suite
- Fedora 26 update for jetty
- Fedora 25 update for jetty, jetty-alpn, jetty-test-helper
- Fedora 24 update for jetty
- Multiple vulnerabilities in IBM Cloudera Observability on Premises with IBM
- Multiple vulnerabilities in IBM Application Performance Management