First published: Fri Dec 31 2004(Updated: )
Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CA Unicenter Web Services Distributed Management | <=3.1 | |
IBM Trading Partner Interchange | <=4.2.2 | |
IBM Trading Partner Interchange | =4.2.1 | |
Mortbay Jetty | =3.1.6 | |
Mortbay Jetty | =3.1.7 | |
Mortbay Jetty | =4.1.0 | |
Mortbay Jetty | =4.1.0_rc4 | |
Mortbay Jetty | =4.1.1 | |
Mortbay Jetty | =4.2.4 | |
Mortbay Jetty | =4.2.5 | |
Mortbay Jetty | =4.2.6 | |
Mortbay Jetty | =4.2.7 | |
Mortbay Jetty | =4.2.9 | |
Mortbay Jetty | =4.2.11 | |
Mortbay Jetty | =4.2.12 | |
Mortbay Jetty | =4.2.14 | |
Mortbay Jetty | =4.2.15 | |
Mortbay Jetty | =4.2.16 | |
Mortbay Jetty | =4.2.17 | |
Mortbay Jetty | =4.2.18 | |
Mortbay Jetty | =4.2.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2478 is classified as a high severity vulnerability due to the potential for remote attackers to read arbitrary files on the server.
To address CVE-2004-2478, upgrade your Jetty HTTP Server and any affected applications to a version that includes the necessary security patches.
CVE-2004-2478 impacts IBM Trading Partner Interchange and CA Unicenter Web Services Distributed Management, among other products that use Jetty.
Yes, CVE-2004-2478 can be exploited remotely, allowing attackers to read sensitive files via specially crafted URLs.
If you are using a vulnerable version related to CVE-2004-2478, it is critical to update to a secure version immediately to mitigate the risk.