The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2015-0201 from the MITRE CVE dictionary dictionary and NIST NVD.
Not vulnerable. The 4.x versions of Spring Framework are not shipped in any Red Hat product as of March 2015.
NOTE: The following CVSS v2 metrics and score provided are preliminary and subject to review.
Base Score | 2.6 |
---|---|
Base Metrics | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Access Vector | Network |
Access Complexity | High |
Authentication | None |
Confidentiality Impact | None |
Integrity Impact | Partial |
Availability Impact | None |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).