CVE-2017-9735: Debian Linux
High severity, CVSS 7.5. EPSS: 5.8% chance of exploitation in the next 30 days.
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
Affected products
- Debian Debian Linux: version 9.0 only
- Eclipse Jetty: before 9.2.22 (fixed in 9.2.22); from 9.3.0, before 9.3.20 (fixed in 9.3.20); from 9.4.0, before 9.4.6 (fixed in 9.4.6)
- Oracle Communications Cloud Native Core Policy: version 1.5.0 only
- Oracle Enterprise Manager Base Platform: version 13.2 only; version 13.3 only
- Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
- Oracle Rest Data Services: version 11.2.0.4 only; version 12.1.0.2 only; version 12.2.0.1 only; version 18c only
- Oracle Retail Xstore Point Of Service: version 7.1 only; version 15.0 only; version 16.0 only; version 17.0 only
Published 2017-06-16. Last modified 2026-06-17.