CVE-2004-2478
Summary
| CVE | CVE-2004-2478 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ca | Unicenter Web Services Distributed Management | All | All | All | All |
| Application | Ibm | Trading Partner Interchange | 4.2.1 | All | All | All |
| Application | Ibm | Trading Partner Interchange | All | All | All | All |
| Application | Jetty | Jetty Http Server | 3.1.6 | All | All | All |
| Application | Jetty | Jetty Http Server | 3.1.7 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.1.0 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.1.0_rc4 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.1.1 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.2.11 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.2.12 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.2.14 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.2.15 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.2.16 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.2.17 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.2.18 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.2.19 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.2.4 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.2.5 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.2.6 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.2.7 | All | All | All |
| Application | Jetty | Jetty Http Server | 4.2.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Secunia - Advisories - IBM Trading Partner Interchange Arbitrary File Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - IBM Trading Partner Interchange May Disclose Files to Remote Users | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Unicenter Web Services Distributed Management Discloses Files to Remote Users - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CA Unicenter Web Service Distributed Management Directory Traversal - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| www.osvdb.org/10490 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Jetty Directory Traversal Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [Full-disclosure] [CAID 34661]: CA Unicenter WSDM File System Read Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.