CVE-2015-0201
10.03.2015, 14:59
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.Enginsight
Vendor | Product | Version |
---|---|---|
pivotal_software | spring_framework | 4.1.0 |
vmware | spring_framework | 4.1.1 |
vmware | spring_framework | 4.1.2 |
vmware | spring_framework | 4.1.3 |
vmware | spring_framework | 4.1.4 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration