First published: Fri Dec 31 2004(Updated: )
Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Trading Partner Interchange | =4.2.1 | |
Eclipse Jetty | =4.1.0_rc4 | |
Eclipse Jetty | =4.2.11 | |
Eclipse Jetty | =4.2.12 | |
Eclipse Jetty | =4.2.7 | |
Eclipse Jetty | =4.2.18 | |
Eclipse Jetty | =4.2.5 | |
Eclipse Jetty | =4.2.19 | |
Eclipse Jetty | =4.2.16 | |
Eclipse Jetty | =4.1.0 | |
Eclipse Jetty | =4.2.4 | |
IBM Trading Partner Interchange | <=4.2.2 | |
CA Unicenter Web Services Distributed Management | <=3.1 | |
Eclipse Jetty | =4.2.15 | |
Eclipse Jetty | =3.1.7 | |
Eclipse Jetty | =4.2.9 | |
Eclipse Jetty | =4.2.6 | |
Eclipse Jetty | =3.1.6 | |
Eclipse Jetty | =4.2.14 | |
Eclipse Jetty | =4.1.1 | |
Eclipse Jetty | =4.2.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.