Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-0201


The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.


Published

2015-03-10T14:59:04.350

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-254

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application pivotal_software spring_framework 4.1.0 Yes
Application vmware spring_framework 4.1.1 Yes
Application vmware spring_framework 4.1.2 Yes
Application vmware spring_framework 4.1.3 Yes
Application vmware spring_framework 4.1.4 Yes

References