// For flags

CVE-2015-0201

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.

El cliente Java SockJS en Pivotal Spring Framework 4.1.x anterior a 4.1.5 genera identificadores de sesiones previsibles, lo que permite a atacantes remotos enviar mensajes a otras sesiones a través de vectores no especificados.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-11-18 CVE Reserved
  • 2015-03-10 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-254: 7PK - Security Features
CAPEC
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Pivotal Software
Search vendor "Pivotal Software"
Spring Framework
Search vendor "Pivotal Software" for product "Spring Framework"
4.1.0
Search vendor "Pivotal Software" for product "Spring Framework" and version "4.1.0"
-
Affected
Vmware
Search vendor "Vmware"
Spring Framework
Search vendor "Vmware" for product "Spring Framework"
4.1.1
Search vendor "Vmware" for product "Spring Framework" and version "4.1.1"
-
Affected
Vmware
Search vendor "Vmware"
Spring Framework
Search vendor "Vmware" for product "Spring Framework"
4.1.2
Search vendor "Vmware" for product "Spring Framework" and version "4.1.2"
-
Affected
Vmware
Search vendor "Vmware"
Spring Framework
Search vendor "Vmware" for product "Spring Framework"
4.1.3
Search vendor "Vmware" for product "Spring Framework" and version "4.1.3"
-
Affected
Vmware
Search vendor "Vmware"
Spring Framework
Search vendor "Vmware" for product "Spring Framework"
4.1.4
Search vendor "Vmware" for product "Spring Framework" and version "4.1.4"
-
Affected