CVE-2019-10246: Eclipse Jetty

Medium severity, CVSS 5.3. EPSS: 4.1% chance of exploitation in the next 30 days.

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

Affected products

  • Eclipse Jetty: version 9.2.27 only; version 9.3.26 only; version 9.4.16 only
  • Netapp Element: affected versions not specified
  • Netapp Oncommand System Manager: from 3.0, up to and including 3.1.3
  • Netapp Snap Creator Framework: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Netapp Snapmanager: affected versions not specified
  • Netapp Storage Replication Adapter For Clustered Data Ontap: from 9.6; version 9.6 only
  • Netapp Storage Services Connector: affected versions not specified
  • Netapp Vasa Provider For Clustered Data Ontap: from 9.6; affected versions not specified
  • Netapp Virtual Storage Console: from 9.6; version 9.6 only
  • Oracle Autovue: version 21.0.2 only
  • Oracle Communications Analytics: version 12.1.1 only
  • Oracle Communications Element Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Communications Services Gatekeeper: version 6.0 only; version 6.1 only; version 7.0 only
  • Oracle Communications Session Report Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Communications Session Route Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Data Integrator: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Endeca Information Discovery Integrator: version 3.2.0 only
  • Oracle Enterprise Manager Base Platform: version 13.2 only; version 13.3 only
  • Oracle Flexcube Core Banking: from 11.5.0, up to and including 11.7.0; version 5.2.0 only
  • Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
  • Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
  • Oracle Rest Data Services: version 11.2.0.4 only; version 12.1.0.2 only; version 12.2.0.1 only; version 18c only
  • Oracle Retail Xstore Point Of Service: version 7.1 only; version 15.0 only; version 16.0 only; version 17.0 only
  • Oracle Unified Directory: version 12.2.1.3.0 only; version 12.2.1.4.0 only

Published 2019-04-22. Last modified 2026-06-17.