Predictable Session IDs in IBM WebSphere Application Server
CVE-2001-0962
Currently unrated
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 19 September 2001
What is CVE-2001-0962?
IBM WebSphere Application Server versions 3.02 to 3.53 utilize predictable session IDs for cookies. This design flaw can be exploited by remote attackers to guess session IDs via brute force methods, potentially allowing them to assume the identities of legitimate users and gain unauthorized privileges within the application.