VulnerabilityModified
CVE-2001-1545
Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing.
MEDIUM 5.0EPSS 1.37%
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Affected
- macromedia/jrun
- Source
- cve@mitre.org
References
- http://www.iss.net/security_center/static/7679.php
- http://www.macromedia.com/v1/handlers/index.cfm?ID=22291&Method=FullPatch, Vendor Advisory
- http://www.securityfocus.com/bid/3665Patch
- http://www.iss.net/security_center/static/7679.php
- http://www.macromedia.com/v1/handlers/index.cfm?ID=22291&Method=FullPatch, Vendor Advisory
- http://www.securityfocus.com/bid/3665Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.