Vulnerability record · CVE-2005-1939 · published 31 December 2005
CVE-2005-1939: Ipswitch WhatsUp Small Business 2004 directory traversal in Report service
Ipswitch · Whatsup Small Business
Ipswitch WhatsUp Small Business 2004 contains a directory traversal flaw in its Report service on TCP port 8022. A remote attacker can supply ".." sequences in a request to read files outside the intended directory. Because the service is network-reachable and unauthenticated, it exposes file contents to anyone who can reach the port.
Description
Directory traversal vulnerability in Ipswitch WhatsUp Small Business 2004 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in a request to the Report service (TCP 8022).
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
high priorityUnauthenticated remote file disclosure with public exploit references and very high EPSS probability, though impact is limited to confidentiality.
What it is
Ipswitch WhatsUp Small Business 2004 contains a directory traversal flaw in its Report service on TCP port 8022. A remote attacker can supply ".." sequences in a request to read files outside the intended directory. Because the service is network-reachable and unauthenticated, it exposes file contents to anyone who can reach the port.
Impact
An attacker gains read access to arbitrary files on the host, which can leak configuration data, credentials or other sensitive content. There is no write or code execution impact described in the record.
Attack surface
Reached over the network via the Report service on TCP 8022; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but multiple references are tagged Exploit and EPSS shows a 30-day probability of 0.63588 (99.177th percentile), indicating high likelihood of exploitation activity.
What to do
- Apply the vendor patch or upgrade WhatsUp Small Business 2004 to a fixed release; the record does not specify fixed versions, so confirm with Ipswitch.
- Restrict access to TCP 8022 to trusted management hosts using firewall or ACL rules.
- Disable the Report service if it is not required.
- Run the service with least privilege and isolate the host on a segmented management network.
Detection
- Monitor network traffic to TCP 8022 for requests containing "../" or encoded traversal sequences.
- Alert on Report service access from hosts outside the expected management subnet.
- Review file access logs on the WhatsUp host for reads of files outside the report directory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://cirt.dk/advisories/cirt-40-advisory.pdf | ExploitVendor Advisory |
| http://secunia.com/advisories/15500 | ExploitVendor Advisory |
| http://secunia.com/secunia_research/2005-14/advisory/ | ExploitVendor Advisory |
| http://securitytracker.com/id?1015141 | Exploit |
| http://www.securityfocus.com/bid/15291 | Exploit |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/22969 | |
| http://cirt.dk/advisories/cirt-40-advisory.pdf | ExploitVendor Advisory |
| http://secunia.com/advisories/15500 | ExploitVendor Advisory |
| http://secunia.com/secunia_research/2005-14/advisory/ | ExploitVendor Advisory |
| http://securitytracker.com/id?1015141 | Exploit |
| http://www.securityfocus.com/bid/15291 | Exploit |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/22969 |
Track CVE-2005-1939 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2005-1939), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.