CVE-2015-2913 Information

Description

server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the java.util.Random class for generation of random Session ID values which makes it easier for remote attackers to predict a value by determining the internal state of the PRNG in this class.

CVSS Vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Reference

https://github.com/orientechnologies/orientdb/commit/668ece96be210e742a4e2820a3085b215cf55104 https://www.kb.cert.org/vuls/id/845332

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

5.9

Share on: