IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2001-09-18 21:00
Updated : 2017-10-09 18:29
NVD link : CVE-2001-0962
Mitre link : CVE-2001-0962
JSON object : View
CWE
Products Affected
ibm
- websphere_application_server
- websphere_commerce_suite