CVE-2019-10247: Debian Linux

Medium severity, CVSS 5.3. EPSS: 5.9% chance of exploitation in the next 30 days.

In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on jetty-distribution and jetty-home will include at the end of the Handler tree a DefaultHandler, which is responsible for reporting this 404 error, it presents the various configured contexts as HTML for users to click through to. This produced HTML includes output that contains the configured fully qualified directory base resource location for each context.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Eclipse Jetty: version 7.0.0 only; version 7.0.1 only; version 7.0.2 only; version 7.1.0 only; version 7.1.1 only; version 7.1.2 only; …
  • Netapp Element: affected versions not specified
  • Netapp Oncommand System Manager: from 3.0, up to and including 3.1.3
  • Netapp Snap Creator Framework: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Netapp Snapmanager: affected versions not specified
  • Netapp Storage Replication Adapter For Clustered Data Ontap: from 9.6
  • Netapp Storage Services Connector: affected versions not specified
  • Netapp Vasa Provider For Clustered Data Ontap: from 9.6
  • Netapp Virtual Storage Console: from 9.6
  • Oracle Autovue: version 21.0.2 only
  • Oracle Communications Analytics: version 12.1.1 only
  • Oracle Communications Element Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Communications Services Gatekeeper: version 6.0 only; version 6.1 only; version 7.0 only
  • Oracle Communications Session Report Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Communications Session Route Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Data Integrator: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Endeca Information Discovery Integrator: version 3.2.0 only
  • Oracle Enterprise Manager Base Platform: version 13.2 only; version 13.3 only
  • Oracle Flexcube Core Banking: from 11.5.0, up to and including 11.7.0; version 5.2.0 only
  • Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
  • Oracle Fmw Platform: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
  • Oracle Retail Xstore Point Of Service: version 7.1 only; version 15.0 only; version 16.0 only; version 17.0 only
  • and 1 more

Published 2019-04-22. Last modified 2026-06-17.