5
CVSSv2

CVE-2009-4609

Published: 13/01/2010 Updated: 08/08/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote malicious users to obtain sensitive information about internal variables and other data via a request to a URI ending in /dump/, as demonstrated by discovering the value of the getPathTranslated variable.

Vulnerable Product Search on Vulmon Subscribe to Product

mortbay jetty 6.1.16

mortbay jetty 6.1.15

mortbay jetty 6.1.12

mortbay jetty 6.1.7

mortbay jetty 6.1.5

mortbay jetty 6.1.20

mortbay jetty 6.1.2

mortbay jetty 6.1.0

mortbay jetty 6.0.0

mortbay jetty 6.1.9

mortbay jetty 6.1.10

mortbay jetty 6.1.4

mortbay jetty 6.1.3

mortbay jetty 6.1.19

mortbay jetty 6.0.2

mortbay jetty 7.0.0

mortbay jetty 6.1.6

mortbay jetty 6.1.1

mortbay jetty 6.1.14

mortbay jetty 6.1.11

mortbay jetty 6.1.8

mortbay jetty 6.0.1