CVE-2018-12538

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.


We have discovered 2,567 live websites that are affected by CVE-2018-12538.

Run a Free Instant Scan




Affected Software

Product  Jetty
Category Web Servers
Vulnerable Domains2,567 live websites (100% of Jetty install base)
Vulnerable Versions
  • from 0 through 9.4.9
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-6 J2EE Misconfiguration: Insufficient Session-ID Length



Details

  • Published - Jun 23, 2018
  • Updated - Aug 5, 2024

Website Distribution by Country

Number of websites using CVE-2018-12538
United States526 websites



Netherlands943 websites
Germany339 websites
Sweden91 websites
China77 websites
Singapore65 websites
Australia52 websites
France49 websites
Norway42 websites
Canada38 websites

Website Distribution by TLD

Number of websites using CVE-2018-12538
.com541 websites
.net215 websites
.de149 websites
.org100 websites
.se44 websites
.edu36 websites
.com.au23 websites
.pl20 websites
.at17 websites
.fr17 websites

Websites affected by CVE-2018-12538

Top websites that are affected by CVE-2018-12538. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.rocks Netherlands**,***
******.***.***.br Brazil**,***
*********.se Sweden**,***
*******.org United States**,***
***.***.at Austria**,***
**********.**.com United States**,***
*****.****.edu United States**,***
***.**********.edu United States**,***
******.***.es Spain***,***
******.com Finland***,***
See full domain list

FAQ

CVE-2018-12538 is J2EE Misconfiguration: Insufficient Session-ID Length in Jetty
A total of 2,567 websites have been identified as vulnerable to CVE-2018-12538, based on global website indexing conducted by WebTechSurvey.
The Jetty is affected by the CVE-2018-12538 vulnerability.
Jetty versions up to 9.4.9 are vulnerable to CVE-2018-12538.
CVE-2018-12538 is resolved in version 9.4.9 of Jetty.