Server-Side Request Forgery (SSRF) in Jetty - CVE-2024-6763
Published: October 14, 2024 / Updated: December 23, 2024
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input in HttpURI. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Enterprise Storage
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
IBM Cloud Pak for Data System
IBM Watson Knowledge Catalog in Cloud Pak for Data
Splunk User Behavior Analytics (UBA)
IBM Sterling Connect:Direct Web Services
IBM Sterling Control Center
Oracle Communications Session Report Manager
Rational Service Tester
Rational Functional Tester (RFT)
Oracle Graph Server and Client
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Cloud Pak for Security
IBM Process Mining
Unified OSS Console Assurance Monitoring (UOCAM)
IBM Cloud Object Storage Systems
UCD - IBM UrbanCode Deploy
IBM Cloud Application Performance Management (APM)
PowerProtect Data Manager
Netezza Appliance
Operations Analytics - Log Analysis
Guardium Data Security Center (GDSC)
Cloudera Observability with IBM
Tivoli Network Manager IP Edition
DataStage on Cloud Pak for Data
IBM Business Automation Manager Open Editions
IBM Engineering Systems Design Rhapsody
Rational Performance Tester
DevOps Test UI
webMethods BPM
Business Automation Insights
IBM Application Suite - IBM Asset Data Dictionary Component
Installation Manager
Packaging Utility
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
StreamSets Data Collector
DevOps Deploy
Storage Protect Server
Maximo Application Suite - IoT Component
Guardium Data Protection
Hybrid Cloud Observability
watsonx.data
Oracle Communications Element Manager
EntireX
Oracle REST Data Services
Oracle Coherence
AMQ Streams
Oracle Retail EFTLink
Orion Platform
HPE Unified OSS Console (UOC)
IBM App Connect Professional
Splunk AppDynamics Machine Agent
Splunk AppDynamics Analytics Agent
jetty-fcgi
jetty-ant
jetty-http-spi
jetty-client
jetty-plus
jetty-jsp
jetty-webapp
jetty-jmx
jetty-cdi
jetty-continuation
jetty-servlet
jetty-util-ajax
jetty-io
jetty-util
jetty-xml
jetty-http
jetty-security
jetty-server
jetty-servlets
jetty-deploy
jetty-jndi
jetty-rewrite
jetty-minimal-javadoc
jetty-proxy
jetty-start
jetty-jaas
jetty-annotations
jetty-quickstart
jetty-openid
Event Streams
IBM InfoSphere Information Server
How to mitigate CVE-2024-6763
IBM Cloud Pak for Data System - update to 1.0.10.0
Operations Analytics - Log Analysis - update to 1.3.8.4
watsonx.data - update to 2.2.1
Guardium Data Security Center (GDSC) - update to 3.6.1
Tivoli Network Manager IP Edition - update to 4.2.0.22
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
DataStage on Cloud Pak for Data - update to 5.2.0
Splunk User Behavior Analytics (UBA) - update to 5.4.3
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.16, 6.4.0.5
IBM Sterling Control Center - addressed in versions 6.3.1.0.4, 6.4.0.0.1
IBM Business Automation Manager Open Editions - update to 8.0.8
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.2.0.4, 10.0.0.2, 10.0.1.2
Rational Performance Tester - update to 11.0.7
Rational Service Tester - update to 11.0.7
DevOps Test UI - update to 11.0.7
EntireX - update to 11.1.1
webMethods BPM - update to 11.1 Fix 6
IBM Business Automation Workflow - addressed in versions 24.0.0-IF006, 24.0.1-IF004
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF008, 24.0.1-IF006, 25.0.0-IF004
Orion Platform - update to 2025.4.1
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.15
Installation Manager - update to 1.10.1.1
Packaging Utility - update to 1.10.1.1
IBM Cloud Pak for Security - update to 1.11.2.0
IBM Process Mining - update to 1.15.0 IF004
AMQ Streams - update to 2
HPE Unified OSS Console (UOC) - update to 3.1.12
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.12
IBM Cloud Object Storage Systems - addressed in versions 3.18.0.84, 3.18.5.40
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
StreamSets Data Collector - update to 7.0.0
UCD - IBM UrbanCode Deploy - addressed in versions 7.0.5.25, 7.1.2.21, 7.2.3.14, 7.3.2.9
IBM App Connect Professional - update to 7.5.5.0.28
DevOps Deploy - addressed in versions 8.0.1.4, 8.1.0.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
Storage Protect Server - update to 8.1.26
Maximo Application Suite - IoT Component - addressed in versions 8.7.19, 8.8.15, 9.0.5
jetty-fcgi - update to 9.4.57-150200.3.31.1
jetty-ant - update to 9.4.57-150200.3.31.1
jetty-http-spi - update to 9.4.57-150200.3.31.1
jetty-client - update to 9.4.57-150200.3.31.1
jetty-plus - update to 9.4.57-150200.3.31.1
jetty-jsp - update to 9.4.57-150200.3.31.1
jetty-webapp - update to 9.4.57-150200.3.31.1
jetty-jmx - update to 9.4.57-150200.3.31.1
jetty-cdi - update to 9.4.57-150200.3.31.1
jetty-continuation - update to 9.4.57-150200.3.31.1
jetty-servlet - update to 9.4.57-150200.3.31.1
jetty-util-ajax - update to 9.4.57-150200.3.31.1
jetty-io - update to 9.4.57-150200.3.31.1
jetty-util - update to 9.4.57-150200.3.31.1
jetty-xml - update to 9.4.57-150200.3.31.1
jetty-http - update to 9.4.57-150200.3.31.1
jetty-security - update to 9.4.57-150200.3.31.1
jetty-server - update to 9.4.57-150200.3.31.1
jetty-servlets - update to 9.4.57-150200.3.31.1
jetty-deploy - update to 9.4.57-150200.3.31.1
jetty-jndi - update to 9.4.57-150200.3.31.1
jetty-rewrite - update to 9.4.57-150200.3.31.1
jetty-minimal-javadoc - update to 9.4.57-150200.3.31.1
jetty-proxy - update to 9.4.57-150200.3.31.1
jetty-start - update to 9.4.57-150200.3.31.1
jetty-jaas - update to 9.4.57-150200.3.31.1
jetty-annotations - update to 9.4.57-150200.3.31.1
jetty-quickstart - update to 9.4.57-150200.3.31.1
jetty-openid - update to 9.4.57-150200.3.31.1
Event Streams - update to 11.6.1
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
Guardium Data Protection - update to 12.0p40
PowerProtect Data Manager - update to 19.19.0-15
Splunk AppDynamics Machine Agent - update to 25.7.0
Splunk AppDynamics Analytics Agent - update to 25.7.0
Hybrid Cloud Observability - update to 2025.4.1
External References
Related Security Bulletins
- SSRF in Eclipse Jetty
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in HPE Unified OSS Console (UOC) and Unified OSS Console Assurance Monitoring (UOCAM)
- IBM App connect professional update for Eclipse Jetty
- Server-Side Request Forgery (SSRF) in Oracle REST Data Services
- Multiple vulnerabilities in Guardium Data Security Center
- Multiple vulnerabilities in IBM Cloud Object System
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Multiple vulnerabilities in IBM Cloud Application Performance Management (APM)
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
- Multiple vulnerabilities in IBM Control Center
- IBM Asset Data Dictionary Component update for Eclipse Jetty
- Server-Side Request Forgery (SSRF) in Oracle Graph Server and Client
- Multiple vulnerabilities in Oracle Communications Session Report Manager
- Multiple vulnerabilities in Oracle Communications Element Manager
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in IBM Installation Manager and IBM Packaging Utility
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Multiple vulnerabilities in IBM Guardium Data Protection
- SUSE update for jetty-minimal
- Multiple vulnerabilities in IBM Tivoli Network Manager IP Edition
- IBM Engineering Systems Design Rhapsody update for Eclipse Jetty
- Multiple vulnerabilities in AMQ Streams
- Multiple vulnerabilities in IBM Watson Knowledge Catalog
- Server-Side Request Forgery (SSRF) in Oracle Coherence
- IBM Storage Protect Server update for Eclipse Jetty
- Splunk User Behavior Analytics (UBA) update for third-party components
- IBM Business Automation Workflow update for Eclipse Jetty
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in IBM Cloudera Observability on Premises with IBM
- IBM watsonx.data update for Eclipse Jetty
- IBM DataStage on Cloud Pak for Data update for Eclipse Jetty
- Splunk AppDynamics Analytics Agent update for third-party components
- Splunk AppDynamics Machine Agent update for third-party components
- Multiple vulnerabilities in SolarWinds Observability
- Multiple vulnerabilities in SolarWinds Platform
- Multiple vulnerabilities in IBM StreamSets Data Collector
- Multiple vulnerabilities in IBM EntireX
- Multiple vulnerabilities in IBM Sterling Connect:Direct Web Services
- Multiple vulnerabilities in IBM Rational Performance Tester
- Multiple vulnerabilities in IBM Rational Service Tester
- Server-Side Request Forgery (SSRF) in Oracle Retail EFTLink
- Multiple vulnerabilities in IBM webMethods BPM
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- IBM Cloud Pak for Data System 2.0 update for Eclipse Jetty
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- IBM Netezza Appliance update for Eclipse Jetty
- Multiple vulnerabilities in IBM Rational Functional Tester / DevOps Test UI