CVE-2015-2080
Inductive Automation Ignition 7.8.1 - Remote Leakage Of Shared Buffers
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
-Decision
Descriptions
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.
El código de manipulación de excepciones en Eclipse Jetty en versiones anteriores a 9.2.9.v20150224 permite a atacantes remotos obtener información sensible de memoria de procesos a través de caracteres no válidos en una cabecera HTTP, vulnerabilidad también conocida como JetLeak.
Remote unauthenticated attackers are able to read arbitrary data from other HTTP sessions because Ignition uses a vulnerable Jetty server. When the Jetty web server receives a HTTP request, the below code is used to parse through the HTTP headers and their associated values. Inductive Automation versions 7.8.1 (b2016012216) and 7.8.0 (b2015101414) are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-02-24 CVE Reserved
- 2015-02-27 CVE Published
- 2016-02-17 First Exploit
- 2024-08-06 CVE Updated
- 2024-10-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/534755/100/1600/threaded | Mailing List | |
http://www.securityfocus.com/bid/72768 | Broken Link | |
http://www.securitytracker.com/id/1031800 | Third Party Advisory | |
https://security.netapp.com/advisory/ntap-20190307-0005 | X_refsource_confirm |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 22 Search vendor "Fedoraproject" for product "Fedora" and version "22" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.2.3 Search vendor "Eclipse" for product "Jetty" and version "9.2.3" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.2.4 Search vendor "Eclipse" for product "Jetty" and version "9.2.4" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.2.5 Search vendor "Eclipse" for product "Jetty" and version "9.2.5" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.2.6 Search vendor "Eclipse" for product "Jetty" and version "9.2.6" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.2.7 Search vendor "Eclipse" for product "Jetty" and version "9.2.7" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.2.8 Search vendor "Eclipse" for product "Jetty" and version "9.2.8" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.0 Search vendor "Eclipse" for product "Jetty" and version "9.3.0" | m0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.0 Search vendor "Eclipse" for product "Jetty" and version "9.3.0" | m1 |
Affected
|