CVE-2017-9735 describes a timing channel vulnerability in Jetty versions through 9.4.x, specifically within the util/security/Password.java component, affecting products like Debian, Eclipse, and Oracle. This flaw allows remote attackers to deduce correct passwords by observing variations in response times for incorrect password attempts. Rated with a CVSS score of 7.5 (High), it presents a low-complexity network attack with high confidentiality impact, though it is not currently listed on the KEV catalog. There is no public exploit intelligence, such as Metasploit or ExploitDB modules, and it has received no community discussion or media coverage, suggesting a low level of active exploitation or public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.2.22CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 9.3.0, < 9.3.20CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 9.4.0, < 9.4.6CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.