CVE Vulnerabilities

CVE-2015-0201

Published: Mar 10, 2015 | Modified: Apr 11, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu

The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Spring_framework Pivotal_software 4.1.0 (including) 4.1.0 (including)
Spring_framework Vmware 4.1.1 (including) 4.1.1 (including)
Spring_framework Vmware 4.1.2 (including) 4.1.2 (including)
Spring_framework Vmware 4.1.3 (including) 4.1.3 (including)
Spring_framework Vmware 4.1.4 (including) 4.1.4 (including)

References