| VID |
22339 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
WWW |
| Detailed Description |
The Jetty HTTP server, according to its banner, has a denial of service vulnerability. Jetty is an open-source based Java HTTP Server and Servlet Engine. Jetty versions prior to 4.2.19 are vulnerable to an unspecified denial of service vulnerability, which may be exploited remotely.
* Note: This check solely relied on the banner of the remote HTTP server to assess this vulnerability, so this might be a false positive.
* References: http://secunia.com/advisories/11166/
* Platforms Affected: Jetty Project, Jetty versions prior to 4.2.19 Linux Any version Unix Any version |
| Recommendation |
Upgrade to the latest version of Jetty (4.2.19 or later), available from the Jetty Web site at http://download.eclipse.org/jetty/ |
| Related URL |
CVE-2004-2381 (CVE) |
| Related URL |
9917 (SecurityFocus) |
| Related URL |
15537 (ISS) |
|