CVE-2017-9735: Debian Linux

High severity, CVSS 7.5. EPSS: 5.8% chance of exploitation in the next 30 days.

Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Eclipse Jetty: before 9.2.22 (fixed in 9.2.22); from 9.3.0, before 9.3.20 (fixed in 9.3.20); from 9.4.0, before 9.4.6 (fixed in 9.4.6)
  • Oracle Communications Cloud Native Core Policy: version 1.5.0 only
  • Oracle Enterprise Manager Base Platform: version 13.2 only; version 13.3 only
  • Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
  • Oracle Rest Data Services: version 11.2.0.4 only; version 12.1.0.2 only; version 12.2.0.1 only; version 18c only
  • Oracle Retail Xstore Point Of Service: version 7.1 only; version 15.0 only; version 16.0 only; version 17.0 only

Published 2017-06-16. Last modified 2026-06-17.