7.5

CVE-2004-2478

Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Data is provided by the National Vulnerability Database (NVD)
IbmTrading Partner Interchange Version <= 4.2.2
IbmTrading Partner Interchange Version4.2.1
JettyJetty Http Server Version3.1.6
JettyJetty Http Server Version3.1.7
JettyJetty Http Server Version4.1.0
JettyJetty Http Server Version4.1.0_rc4
JettyJetty Http Server Version4.1.1
JettyJetty Http Server Version4.2.4
JettyJetty Http Server Version4.2.5
JettyJetty Http Server Version4.2.6
JettyJetty Http Server Version4.2.7
JettyJetty Http Server Version4.2.9
JettyJetty Http Server Version4.2.11
JettyJetty Http Server Version4.2.12
JettyJetty Http Server Version4.2.14
JettyJetty Http Server Version4.2.15
JettyJetty Http Server Version4.2.16
JettyJetty Http Server Version4.2.17
JettyJetty Http Server Version4.2.18
JettyJetty Http Server Version4.2.19
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.68% 0.868
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P