Vulnerability Name: | CVE-2001-1534 (CCN-7494) | ||||||||
Assigned: | 2001-11-07 | ||||||||
Published: | 2001-11-07 | ||||||||
Updated: | 2021-07-15 | ||||||||
Summary: | mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-384 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: BUGTRAQ Type: Broken Link 20011113 Brute-Forcing Web Application Session IDs Source: MITRE Type: CNA CVE-2001-1534 Source: CCN Type: iDefense iAlert White Paper - November 2001 Brute-Force Exploitation of Web Application Session Ids Source: XF Type: Broken Link apache-modusertrack-predicticable-sessionid(7494) Source: CCN Type: OSVDB ID: 20242 Apache HTTP Server mod_usertrack Predictable Session ID Generation Source: BID Type: Third Party Advisory, VDB Entry 3521 Source: CCN Type: BID-3521 Apache mod_usertrack Predictable ID Generation Vulnerability Source: XF Type: UNKNOWN apache-modusertrack-predicticable-sessionid(7494) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |