First published: Fri Dec 31 2004(Updated: )
Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Trading Partner Interchange | =4.2.1 | |
Jetty Jetty Http Server | =4.1.0_rc4 | |
Jetty Jetty Http Server | =4.2.11 | |
Jetty Jetty Http Server | =4.2.12 | |
Jetty Jetty Http Server | =4.2.7 | |
Jetty Jetty Http Server | =4.2.18 | |
Jetty Jetty Http Server | =4.2.5 | |
Jetty Jetty Http Server | =4.2.19 | |
Jetty Jetty Http Server | =4.2.16 | |
Jetty Jetty Http Server | =4.1.0 | |
Jetty Jetty Http Server | =4.2.4 | |
IBM Trading Partner Interchange | <=4.2.2 | |
CA Unicenter Web Services Distributed Management | <=3.1 | |
Jetty Jetty Http Server | =4.2.15 | |
Jetty Jetty Http Server | =3.1.7 | |
Jetty Jetty Http Server | =4.2.9 | |
Jetty Jetty Http Server | =4.2.6 | |
Jetty Jetty Http Server | =3.1.6 | |
Jetty Jetty Http Server | =4.2.14 | |
Jetty Jetty Http Server | =4.1.1 | |
Jetty Jetty Http Server | =4.2.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.