First published: Wed Sep 19 2001(Updated: )
IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Commerce Suite | =3.2 | |
Ibm Websphere Application Server | <=3.5.3 | |
IBM WebSphere Commerce Suite | =3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.