IBM WebSphere Application Server Predictable Session ID Vulnerability

Bugtraq ID: 3349
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Sep 19 2001 12:00AM
Updated: Sep 19 2001 12:00AM
Credit: This vulnerability was submitted to BugTraq on September 19th, 2001 by Mark Heuse <marc@suse.de>.
Vulnerable: IBM WebSphere Commerce Suite Service Provider 3.2
IBM WebSphere Commerce Suite Service Provider 3.1.2
IBM WebSphere Application Server Advanced Edition 3.0 .2.1
- IBM AIX 4.3
- Linux kernel 2.3 .x
- Microsoft Windows NT 4.0
- Sun Solaris 8_sparc
IBM Websphere Application Server 3.5.3
- IBM AIX 4.3
- Linux kernel 2.3 .x
- Microsoft Windows NT 4.0
- Sun Solaris 8_sparc
IBM Websphere Application Server 3.5.2
- IBM AIX 4.3
- Linux kernel 2.3 .x
- Microsoft Windows NT 4.0
- Sun Solaris 8_sparc
IBM Websphere Application Server 3.5.1
- IBM AIX 4.3
- Linux kernel 2.3 .x
- Microsoft Windows NT 4.0
- Sun Solaris 8_sparc
IBM Websphere Application Server 3.0 .2.4
- IBM AIX 4.3
- Linux kernel 2.3 .x
- Microsoft Windows NT 4.0
- Sun Solaris 8_sparc
IBM Websphere Application Server 3.0 .2.3
- IBM AIX 4.3
- Linux kernel 2.3 .x
- Microsoft Windows NT 4.0
- Sun Solaris 8_sparc
IBM Websphere Application Server 3.0 .2.2
- IBM AIX 4.3
- Linux kernel 2.3 .x
- Microsoft Windows NT 4.0
- Sun Solaris 8_sparc
Not Vulnerable: IBM WebSphere Application Server Enterprise Edition 4.0
- IBM AIX 4.3
- Linux kernel 2.3 .x
- Microsoft Windows NT 4.0
- Sun Solaris 8_sparc


 

Privacy Statement
Copyright 2010, SecurityFocus