← Back

CVE-2001-0962

nvd nist
Published: Sep 19, 2001Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.

Affected (3)

2 products
Websphere Application Server
Websphere Commerce Suite
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.5.3
Ibm
Version 3.1.2
Version 3.2

Timeline

No history available yet.