5
CVSSv2

CVE-2015-0201

Published: 10/03/2015 Updated: 11/04/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Java SockJS client in Pivotal Spring Framework 4.1.x prior to 4.1.5 generates predictable session ids, which allows remote malicious users to send messages to other sessions via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pivotal software spring framework 4.1.0

vmware spring framework 4.1.2

vmware spring framework 4.1.4

vmware spring framework 4.1.1

vmware spring framework 4.1.3

Vendor Advisories

The Java SockJS client in Pivotal Spring Framework 41x before 415 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors ...

Github Repositories

CVE assignment documentation

CVE-HOWTO CVE assignment documentation - this document replaces peopleredhatcom/kseifrie/CVE-OpenSource-Request-HOWTOhtml Please note that this document pertains to CVE's for issues found in Open Source programs, not closed source programs, if you need a CVE for a closed source program I suggest you go to MITRE directly Copyright: Red Hat 2016 Author: Kurt Seifr