CVE-2006-6969: Medium severity Jetty Jetty HTTP server vulnerability
Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6969?
CVE-2006-6969 is considered a high severity vulnerability due to its potential to allow unauthorized access through predictable session identifiers.
How do I fix CVE-2006-6969?
To fix CVE-2006-6969, upgrade to Jetty version 6.1.0pre3, 6.0.2, 5.1.12, or 4.2.27.
What systems are affected by CVE-2006-6969?
CVE-2006-6969 affects Jetty versions before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3.
Can CVE-2006-6969 be exploited remotely?
Yes, attackers can exploit CVE-2006-6969 remotely by guessing session identifiers through brute force attacks.
What type of vulnerability is CVE-2006-6969 classified as?
CVE-2006-6969 is classified as a session management vulnerability related to predictable session identifiers.