CWE-6: J2EE Misconfiguration: Insufficient Session-ID Length

low-risk

The J2EE application is configured to use an insufficient session ID length.

Abstraction: Variant

Common Consequences

Access Control Gain Privileges or Assume Identity

Real-World Examples (1)

CVE CVSS EPSS KEV
CVE-2018-12538 8.8 0.5%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal