Unrated severityNVD Advisory· Published Sep 19, 2001· Updated Jun 16, 2026
CVE-2001-0962
CVE-2001-0962
Description
IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
Affected products
4cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*range: <=3.5.3
- (no CPE)range: >=3.02, <=3.53
cpe:2.3:a:ibm:websphere_commerce_suite:3.1.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:websphere_commerce_suite:3.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_commerce_suite:3.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.