Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-12538


In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.


Published

2018-06-22T19:29:00.220

Last Modified

2024-11-21T03:45:23.610

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-6
  • Type: Primary
    CWE-384

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application eclipse jetty ≤ 9.4.8 Yes
Application netapp e-series_santricity_management_plug-ins - Yes
Application netapp e-series_santricity_os_controller ≤ 11.40 Yes
Application netapp e-series_santricity_web_services_proxy - Yes
Application netapp element_software - Yes
Application netapp hyper_converged_infrastructure - Yes
Application netapp oncommand_system_manager ≤ 3.1.3 Yes
Application netapp oncommand_unified_manager - Yes
Application netapp santricity_cloud_connector - Yes
Application netapp snap_creator_framework - Yes
Application netapp snapcenter - Yes
Application netapp snapmanager - Yes

References