Vulnerability Description
server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the java.util.Random class for generation of random Session ID values, which makes it easier for remote attackers to predict a value by determining the internal state of the PRNG in this class.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Orientdb | Orientdb | 2.0.14 |
Related Weaknesses (CWE)
References
- https://github.com/orientechnologies/orientdb/commit/668ece96be210e742a4e2820a30Vendor Advisory
- https://www.kb.cert.org/vuls/id/845332Third Party AdvisoryUS Government Resource
- https://github.com/orientechnologies/orientdb/commit/668ece96be210e742a4e2820a30Vendor Advisory
- https://www.kb.cert.org/vuls/id/845332Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2015-2913?
CVE-2015-2913 is a vulnerability with a CVSS score of 5.9 (MEDIUM). server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the java.util.Random class ...
How severe is CVE-2015-2913?
CVE-2015-2913 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2913?
Check the references section above for vendor advisories and patch information. Affected products include: Orientdb Orientdb.