CVE-2001-1534
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session…
Does this matter?
Lower severity and a low EPSS score (0.70%). Track it; it rarely justifies an emergency change on its own.
Description
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.70% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-384
- Affected
- apache/http server
- Source
- cve@mitre.org
References
- http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00084.htmlBroken Link
- http://www.iss.net/security_center/static/7494.phpBroken Link
- http://www.securityfocus.com/bid/3521Third Party Advisory, VDB Entry
- http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00084.htmlBroken Link
- http://www.iss.net/security_center/static/7494.phpBroken Link
- http://www.securityfocus.com/bid/3521Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.