← Back

CVE-2004-2478

nvd nist
Published: Dec 31, 2004Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Affected (21)

1 product
1 product
Trading Partner Interchange
1 product
Jetty Http Server
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.1
Ibm
Up to 4.2.2
Version 4.2.1
Jetty
Version 3.1.6
Version 3.1.7
Version 4.1.0
Version 4.1.0_rc4
Version 4.1.1
Version 4.2.11
Version 4.2.12
Version 4.2.14
Version 4.2.15
Version 4.2.16
Version 4.2.17
Version 4.2.18
Version 4.2.19
Version 4.2.4
Version 4.2.5
Version 4.2.6
Version 4.2.7
Version 4.2.9

References (22)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.