Back

CVE-2004-2478

Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Published: Dec 31, 2004 Modified: Jun 16, 2026
NVD-CWE-noinfo

CVSS Metrics

Affected Products (21)

Vendor Product Version
ca unicenter_web_services_distributed_management *
ibm trading_partner_interchange *
ibm trading_partner_interchange 4.2.1
jetty jetty_http_server 3.1.6
jetty jetty_http_server 3.1.7
jetty jetty_http_server 4.1.0
jetty jetty_http_server 4.1.0_rc4
jetty jetty_http_server 4.1.1
jetty jetty_http_server 4.2.4
jetty jetty_http_server 4.2.5
jetty jetty_http_server 4.2.6
jetty jetty_http_server 4.2.7
jetty jetty_http_server 4.2.9
jetty jetty_http_server 4.2.11
jetty jetty_http_server 4.2.12
jetty jetty_http_server 4.2.14
jetty jetty_http_server 4.2.15
jetty jetty_http_server 4.2.16
jetty jetty_http_server 4.2.17
jetty jetty_http_server 4.2.18

…and 1 more

GitHub Security Advisory GHSA-mcvw-pw2f-v47r

Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.42%

Top 17% most likely to be exploited

Threat Score 30.7 / 100

Data Sources

NVD EPSS GitHub