CVE-2015-0201
10.03.2015, 14:59
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.Enginsight
| Vendor | Product | Version |
|---|---|---|
| pivotal_software | spring_framework | 4.1.0 |
| vmware | spring_framework | 4.1.1 |
| vmware | spring_framework | 4.1.2 |
| vmware | spring_framework | 4.1.3 |
| vmware | spring_framework | 4.1.4 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration