peter bassill · operator
$ cve CVE-2021-28164 JSON

CVE-2021-28164 EXPLOIT

5.3
MEDIUM · CVSS 3.1 · EPSS 82.4% (pctl 100)

Patch early

A public exploit exists.

Description

In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS82.37% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2021-04-01
Last modified2026-06-17

Affected (17)

VendorProduct
eclipsejetty
netappcloud manager
netappe-series performance analyzer
netappe-series santricity os controller
netappe-series santricity web services
netappelement plug-in for vcenter server
netappsantricity cloud connector
netappsnapcenter
netappsnapcenter plug-in
netappstorage replication adapter for clustered data ontap
netappvasa provider for clustered data ontap
netappvirtual storage console
oracleautovue for agile product lifecycle management
oraclebanking apis
oraclebanking digital experience
oraclecommunications session route manager
oraclesiebel core - automation

Public exploits

SourceTitleDate
exploit-dbJetty 9.4.37.v20210219 - Information Disclosure2021-10-22

References

→ the Explorer  ·  watch your stack  ·  NVD