AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2004-2478

HIGH · CVSS 7.5 EPSS 2.42%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2004-12-31 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2004-2478
Severity
HIGH
CVSS
7.5
EPSS
2.42%

Original Filing — NVD Description

Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.