Unrated severityNVD Advisory· Published Sep 19, 2001· Updated Apr 16, 2026
CVE-2001-0962
CVE-2001-0962
Description
IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
Affected products
3- cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*Range: <=3.5.3
cpe:2.3:a:ibm:websphere_commerce_suite:3.1.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:websphere_commerce_suite:3.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_commerce_suite:3.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.