CVE-2004-2478: High severity CA Unicenter Web Services Distributed Management vulnerability
Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2478?
CVE-2004-2478 is classified as a high severity vulnerability due to the potential for remote attackers to read arbitrary files on the server.
How do I fix CVE-2004-2478?
To address CVE-2004-2478, upgrade your Jetty HTTP Server and any affected applications to a version that includes the necessary security patches.
Which products are affected by CVE-2004-2478?
CVE-2004-2478 impacts IBM Trading Partner Interchange and CA Unicenter Web Services Distributed Management, among other products that use Jetty.
Can CVE-2004-2478 be exploited remotely?
Yes, CVE-2004-2478 can be exploited remotely, allowing attackers to read sensitive files via specially crafted URLs.
What should I do if I am using a vulnerable version related to CVE-2004-2478?
If you are using a vulnerable version related to CVE-2004-2478, it is critical to update to a secure version immediately to mitigate the risk.