{"api_version":"1","generated_at":"2026-07-23T09:13:43+00:00","cve":"CVE-2005-4804","urls":{"html":"https://cve.report/CVE-2005-4804","api":"https://cve.report/api/cve/CVE-2005-4804.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4804","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4804"},"summary":{"title":"CVE-2005-4804","description":"Unspecified vulnerability in Sun Java System Application Server Platform Edition and Enterprise Edition 8.1 2005 Q1, and Platform Edition UR1, allows remote attackers to read .jar files via unknown vectors related to deployed web applications.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22261","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22261","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/16802","name":"http://secunia.com/advisories/16802","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - Sun Java System Application Server JAR File Content Disclosure","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/1733","name":"http://www.vupen.com/english/advisories/2005/1733","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/14823","name":"http://www.securityfocus.com/bid/14823","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Sun Java System Application Server Web Application JAR Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-101905-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-101905-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"#101905: Security Vulnerability in Sun Java System Application Server Exposes Contents of \"jar\" File of Deployed Web Applications","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.ciac.org/ciac/bulletins/p-305.shtml","name":"http://www.ciac.org/ciac/bulletins/p-305.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"P-305: Sun JAR File Contents Disclosure","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4804","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4804","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4804","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"java_system_application_server","cpe6":"8.1","cpe7":"*","cpe8":"enterprise","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4804","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"java_system_application_server","cpe6":"8.1","cpe7":"*","cpe8":"platform","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4804","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"java_system_application_server","cpe6":"8.1","cpe7":"ur1","cpe8":"platform","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:01:23.177Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"16802","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/16802"},{"name":"sun-java-jar-file-information-disclosure(22261)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22261"},{"name":"ADV-2005-1733","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/1733"},{"name":"P-305","tags":["third-party-advisory","government-resource","x_refsource_CIAC","x_transferred"],"url":"http://www.ciac.org/ciac/bulletins/p-305.shtml"},{"name":"101905","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-101905-1"},{"name":"14823","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14823"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-09-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in Sun Java System Application Server Platform Edition and Enterprise Edition 8.1 2005 Q1, and Platform Edition UR1, allows remote attackers to read .jar files via unknown vectors related to deployed web applications."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"16802","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/16802"},{"name":"sun-java-jar-file-information-disclosure(22261)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22261"},{"name":"ADV-2005-1733","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/1733"},{"name":"P-305","tags":["third-party-advisory","government-resource","x_refsource_CIAC"],"url":"http://www.ciac.org/ciac/bulletins/p-305.shtml"},{"name":"101905","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-101905-1"},{"name":"14823","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14823"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4804","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in Sun Java System Application Server Platform Edition and Enterprise Edition 8.1 2005 Q1, and Platform Edition UR1, allows remote attackers to read .jar files via unknown vectors related to deployed web applications."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"16802","refsource":"SECUNIA","url":"http://secunia.com/advisories/16802"},{"name":"sun-java-jar-file-information-disclosure(22261)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22261"},{"name":"ADV-2005-1733","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/1733"},{"name":"P-305","refsource":"CIAC","url":"http://www.ciac.org/ciac/bulletins/p-305.shtml"},{"name":"101905","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-101905-1"},{"name":"14823","refsource":"BID","url":"http://www.securityfocus.com/bid/14823"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4804","datePublished":"2006-05-25T10:00:00.000Z","dateReserved":"2006-05-25T00:00:00.000Z","dateUpdated":"2024-08-08T00:01:23.177Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sun:java_system_application_server:8.1:*:enterprise:*:*:*:*:*","matchCriteriaId":"D9F68042-8C22-447E-8C6B-F44DEE5BF389"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:java_system_application_server:8.1:*:platform:*:*:*:*:*","matchCriteriaId":"7659FD2B-6F83-44F1-B4A1-94D106B4C686"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:java_system_application_server:8.1:ur1:platform:*:*:*:*:*","matchCriteriaId":"E2A9B4B2-B844-411F-B4C7-9AC60C37A5A3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4804","Ordinal":"1","Title":"CVE-2005-4804","CVE":"CVE-2005-4804","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4804","Ordinal":"1","NoteData":"Unspecified vulnerability in Sun Java System Application Server Platform Edition and Enterprise Edition 8.1 2005 Q1, and Platform Edition UR1, allows remote attackers to read .jar files via unknown vectors related to deployed web applications.","Type":"Description","Title":"CVE-2005-4804"},{"CveYear":"2005","CveId":"4804","Ordinal":"2","NoteData":"2006-05-25","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4804","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}