Back to Database
Status published
Medium
CVE-2009-5046
JSP Dump and Session Dump Servlet XSS in jetty before...
Vulnerability Description
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-5046
Credits & Attribution
No credits recorded in the NVD database.
References
More from eclipse
View All →CVE-2023-41900
Jetty's OpenId Revoked authentication allows one request
Low
3.5
CVE-2023-40167
Jetty accepts "+" prefixed value in Content-Length
Medium
5.3
CVE-2023-36479
Jetty vulnerable to errant command quoting in CGI Servlet
Low
3.5
CVE-2023-36478
HTTP/2 HPACK integer overflow and buffer allocation
High
7.5
CVE-2023-26049
Cookie parsing of quoted values can exfiltrate values from other cookies in Eclipse Jetty
Low
2.4
Affected Vendor
eclipse
View all reports →Affected Software
jetty, debian linux
Vulnerable Versions:
0, 8.0
Timeline
Official Publish:
November 6th, 2019
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.