VendorsJettyjetty_http_server4.2.17
Vulnerabilities

Jetty Jetty HTTP Server 4.2.17

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2004-2478
Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
Published 2005-08-21 · Modified
7.5EPSS 0.024
CVE-2006-6969
Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.
Published 2007-02-07 · Modified
6.8EPSS 0.016
CVE-2004-2381
HttpRequest.java in Jetty HTTP Server before 4.2.19 allows remote attackers to cause denial of service (memory usage and application crash) via HTTP requests with a large Content-Length.
Published 2005-08-16 · Modified
5.0EPSS 0.018