For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "netapp:e-series_santricity_os_controller",
"extracted_events": [
{
"introduced": "11.0"
},
{
"last_affected": "11.70.1"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:autovue_for_agile_product_lifecycle_management:21.0.2:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:autovue_for_agile_product_lifecycle_management",
"extracted_events": [
{
"last_affected": "21.0.2"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.10.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_cloud_native_core_binding_support_function",
"extracted_events": [
{
"last_affected": "1.10.0"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.5.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_cloud_native_core_security_edge_protection_proxy",
"extracted_events": [
{
"last_affected": "1.5.0"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.14.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_cloud_native_core_service_communication_proxy",
"extracted_events": [
{
"last_affected": "1.14.0"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.14.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:communications_cloud_native_core_unified_data_repository",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "1.14.0"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_diameter_signaling_router",
"extracted_events": [
{
"introduced": "8.0.0.0"
},
{
"last_affected": "8.5.0.2"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.3.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:financial_services_crime_and_compliance_management_studio",
"extracted_events": [
{
"last_affected": "8.0.8.2.0"
},
{
"last_affected": "8.0.8.3.0"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:rest_data_services:*:*:*:*:-:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:rest_data_services",
"extracted_events": [
{
"fixed": "22.1.1"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:retail_eftlink:20.0.1:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:retail_eftlink",
"extracted_events": [
{
"last_affected": "20.0.1"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:stream_analytics:*:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:stream_analytics:19c:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "oracle:stream_analytics",
"extracted_events": [
{
"fixed": "19.1.0.0.6.4"
},
{
"last_affected": "19c"
}
]
}
]
}