CWE-6 · 1 records
J2EE Misconfiguration: Insufficient Session-ID Length
CVEs in this class
1 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2018-12538No exploit | In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSeseclipse · jetty · CWE-6 | High8.8 | — | 2.7% | Jun 22, 2018 |
- CVE-2018-1253836Monitor
In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSes
HighCVSS 8.8No exploitEPSS 3%eclipse · jettyJun 22, 2018