6.8

CVE-2006-6969

Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.

Data is provided by the National Vulnerability Database (NVD)
JettyJetty Http Server Version4.2.9
JettyJetty Http Server Version4.2.11
JettyJetty Http Server Version4.2.12
JettyJetty Http Server Version4.2.14
JettyJetty Http Server Version4.2.15
JettyJetty Http Server Version4.2.16
JettyJetty Http Server Version4.2.17
JettyJetty Http Server Version4.2.18
JettyJetty Http Server Version4.2.19
JettyJetty Http Server Version4.2.24
JettyJetty Http Server Version5.1.11
JettyJetty Http Server Version6.0.1
JettyJetty Http Server Version6.1.0_pre2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.67% 0.704
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P