Description
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
Remediation
References
https://pivotal.io/security/cve-2015-0201
Related Vulnerabilities
CVE-2019-5786 Vulnerability in npm package puppeteer
CVE-2019-10447 Vulnerability in maven package io.jenkins.plugins:sofy-ai
CVE-2019-20503 Vulnerability in npm package electron
CVE-2020-2220 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-11969 Vulnerability in maven package org.apache.tomee:openejb-lite