Brute-force attack in Jetty - CVE-2017-9735

 

Brute-force attack in Jetty - CVE-2017-9735

Published: June 17, 2017 / Updated: November 22, 2023


Vulnerability identifier: #VU9654
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9735
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a brute-force attack.

The vulnerability exists due to a timing channel in util/security/Password.java, which allows a remote attacker to perform a brute-force attack by observing elapsed times before rejection of incorrect passwords.


Affected software

Jetty
Security Directory Integrator
Cloudera Observability with IBM
Dell Support Assist Enterprise
IBM Security Verify Directory
IBM Security Directory Suite
CloudLink
Oracle Communications Cloud Native Core Policy
Crowd Server
Crowd Data Center
IBM Cloud Application Performance Management (APM)
Jira Software Data Center
IBM Spectrum Protect Storage Agent
Jira Software Server
Fedora
jetty-test-helper
jetty-alpn
jetty

How to mitigate CVE-2017-9735

Update to version 9.4.6.v20170531, 9.3.20.v20170531 or jetty-9.2.22.v20170606.

Dell Support Assist Enterprise - update to 4.00.06.00
Crowd Server - addressed in versions 5.0.11, 5.1.9, 5.2.4
Crowd Data Center - addressed in versions 5.0.11, 5.1.9, 5.2.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
Jira Software Data Center - addressed in versions 8.20.27, 9.10.2, 9.11.1
Jira Software Server - addressed in versions 8.20.27, 9.10.2, 9.11.1
jetty-test-helper - update to 3.1-3.fc25
IBM Security Directory Suite - update to 8.0.1.21
CloudLink - update to 8.0-3.10.5.1
jetty-alpn - update to 8.1.11-2.v20170118.fc25
IBM Spectrum Protect Storage Agent - update to 8.1.19
jetty - addressed in versions 9.3.7-3.v20160115.fc24, 9.4.6-1.v20170531.fc25, 9.4.6-1.v20170531.fc26

External References

Related Security Bulletins