CWE-6Variant

J2EE Misconfiguration: Insufficient Session-ID Length

Incomplete in the CWE catalog · 1 CVE mapped

1
CVEs mapped
What it is

The J2EE application is configured to use an insufficient session ID length.

Recent examples
none
CVE-2018-12538

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is…

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.

no explanation yet
3%
epss
The record
Technical detail
CWE ID
CWE-6
Abstraction
Variant
Structure
Simple
Status
Incomplete
References (2)