CVE-2004-2478

Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ca:unicenter_web_services_distributed_management:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:trading_partner_interchange:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:trading_partner_interchange:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:3.1.6:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:3.1.7:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.1.0_rc4:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.2.4:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.2.5:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.2.6:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.2.7:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.2.9:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.2.11:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.2.12:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.2.14:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.2.15:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.2.16:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.2.17:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.2.18:*:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty_http_server:4.2.19:*:*:*:*:*:*:*

History

20 Nov 2024, 23:53

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/049846.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/049846.html -
References () http://secunia.com/advisories/12703 - Vendor Advisory () http://secunia.com/advisories/12703 - Vendor Advisory
References () http://secunia.com/advisories/22229 - Vendor Advisory () http://secunia.com/advisories/22229 - Vendor Advisory
References () http://securitytracker.com/id?1011545 - () http://securitytracker.com/id?1011545 -
References () http://securitytracker.com/id?1016975 - () http://securitytracker.com/id?1016975 -
References () http://www-1.ibm.com/support/docview.wss?uid=swg21178665 - Vendor Advisory () http://www-1.ibm.com/support/docview.wss?uid=swg21178665 - Vendor Advisory
References () http://www.osvdb.org/10490 - () http://www.osvdb.org/10490 -
References () http://www.securityfocus.com/archive/1/447648/100/0/threaded - () http://www.securityfocus.com/archive/1/447648/100/0/threaded -
References () http://www.securityfocus.com/bid/11330 - () http://www.securityfocus.com/bid/11330 -
References () http://www.vupen.com/english/advisories/2006/3873 - Vendor Advisory () http://www.vupen.com/english/advisories/2006/3873 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/17600 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/17600 -

Information

Published : 2004-12-31 05:00

Updated : 2024-11-20 23:53


NVD link : CVE-2004-2478

Mitre link : CVE-2004-2478

CVE.ORG link : CVE-2004-2478


JSON object : View

Products Affected

jetty

  • jetty_http_server

ca

  • unicenter_web_services_distributed_management

ibm

  • trading_partner_interchange