Логотип exploitDog
bind:CVE-2015-2913
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-2913

Количество 2

Количество 2

nvd логотип

CVE-2015-2913

около 10 лет назад

server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the java.util.Random class for generation of random Session ID values, which makes it easier for remote attackers to predict a value by determining the internal state of the PRNG in this class.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-v6wr-fch2-vm5w

больше 7 лет назад

OrientDB Server Community Edition uses insufficiently random values to generate session IDs

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2015-2913

server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the java.util.Random class for generation of random Session ID values, which makes it easier for remote attackers to predict a value by determining the internal state of the PRNG in this class.

CVSS3: 5.9
1%
Низкий
около 10 лет назад
github логотип
GHSA-v6wr-fch2-vm5w

OrientDB Server Community Edition uses insufficiently random values to generate session IDs

CVSS3: 5.9
1%
Низкий
больше 7 лет назад

Уязвимостей на страницу