CWE-6
1 CVE • Abstraction: Variant
J2EE Misconfiguration: Insufficient Session-ID Length
The J2EE application is configured to use an insufficient session ID length.
CVEs (1)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Eclipse Netapp12E Series Santricity Management Plug Ins E Series Santricity Os ControllerE Series Santricity Web Services Proxy+9 moreNov 21, 2024 Jun 22, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSes...Show more |