The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
| Software | From | Fixed in |
|---|---|---|
| pivotal_software / spring_framework | 4.1.0 | 4.1.0.x |
| vmware / spring_framework | 4.1.1 | 4.1.1.x |
| vmware / spring_framework | 4.1.2 | 4.1.2.x |
| vmware / spring_framework | 4.1.3 | 4.1.3.x |
| vmware / spring_framework | 4.1.4 | 4.1.4.x |
org.springframework / spring-core
|
4.1.0 | 4.1.5 |