CVE-2004-2478
Last modified
CVE-2004-2478 is a vulnerability of currently unknown severity. Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.. EPSS estimates a 2.42% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ca | Unicenter Web Services Distributed Management | <= 3.1 |
| Ibm | Trading Partner Interchange | <= 4.2.2 |
| Ibm | Trading Partner Interchange | 4.2.1 |
| Jetty | Jetty Http Server | 3.1.6 |
| Jetty | Jetty Http Server | 3.1.7 |
| Jetty | Jetty Http Server | 4.1.0 |
| Jetty | Jetty Http Server | 4.1.0_rc4 |
| Jetty | Jetty Http Server | 4.1.1 |
| Jetty | Jetty Http Server | 4.2.4 |
| Jetty | Jetty Http Server | 4.2.5 |
| Jetty | Jetty Http Server | 4.2.6 |
| Jetty | Jetty Http Server | 4.2.7 |
| Jetty | Jetty Http Server | 4.2.9 |
| Jetty | Jetty Http Server | 4.2.11 |
| Jetty | Jetty Http Server | 4.2.12 |
| Jetty | Jetty Http Server | 4.2.14 |
| Jetty | Jetty Http Server | 4.2.15 |
| Jetty | Jetty Http Server | 4.2.16 |
| Jetty | Jetty Http Server | 4.2.17 |
| Jetty | Jetty Http Server | 4.2.18 |
| Jetty | Jetty Http Server | 4.2.19 |
References
- http://secunia.com/advisories/12703Vendor Advisory
- http://secunia.com/advisories/22229Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg21178665Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3873Vendor Advisory
- http://secunia.com/advisories/12703Vendor Advisory
- http://secunia.com/advisories/22229Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg21178665Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3873Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2478?
How severe is CVE-2004-2478?
How do I fix CVE-2004-2478?
Are you affected by CVE-2004-2478?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
