The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Spring_framework | Pivotal_software | 4.1.0 (including) | 4.1.0 (including) |
Spring_framework | Vmware | 4.1.1 (including) | 4.1.1 (including) |
Spring_framework | Vmware | 4.1.2 (including) | 4.1.2 (including) |
Spring_framework | Vmware | 4.1.3 (including) | 4.1.3 (including) |
Spring_framework | Vmware | 4.1.4 (including) | 4.1.4 (including) |