CVE-2001-1545: Medium severity Macromedia JRun vulnerability
Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1545?
CVE-2001-1545 is considered a high severity vulnerability due to its potential for session hijacking.
How do I fix CVE-2001-1545?
To fix CVE-2001-1545, it is recommended to upgrade to a newer version of JRun that does not append session identifiers to URLs.
What types of systems are affected by CVE-2001-1545?
CVE-2001-1545 affects Macromedia JRun versions 3.0 and 3.1.
What are the risks associated with CVE-2001-1545?
The primary risk associated with CVE-2001-1545 is the unauthorized access to user sessions due to exposed session IDs.
Can CVE-2001-1545 be exploited remotely?
Yes, CVE-2001-1545 can be exploited remotely by attackers who can intercept or manipulate HTTP referrer fields.