Predictable Session IDs in IBM WebSphere Application Server
CVE-2001-0962

Currently unrated

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 September 2001

What is CVE-2001-0962?

IBM WebSphere Application Server versions 3.02 to 3.53 utilize predictable session IDs for cookies. This design flaw can be exploited by remote attackers to guess session IDs via brute force methods, potentially allowing them to assume the identities of legitimate users and gain unauthorized privileges within the application.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.