{"api_version":"1","generated_at":"2026-07-23T04:34:47+00:00","cve":"CVE-2001-1534","urls":{"html":"https://cve.report/CVE-2001-1534","api":"https://cve.report/api/cve/CVE-2001-1534.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-1534","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-1534"},"summary":{"title":"CVE-2001-1534","description":"mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.","state":"PUBLISHED","assigner":"mitre","published_at":"2001-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-384","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00084.html","name":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00084.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Brute-Forcing Web Application Session IDs","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/7494.php","name":"http://www.iss.net/security_center/static/7494.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"ISS X-Force Database:","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/3521","name":"http://www.securityfocus.com/bid/3521","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Apache mod_usertrack Predictable ID Generation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-1534","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-1534","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"1534","vulnerable":"1","versionEndIncluding":"1.3.20","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"http_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2001-1534","organization":"Red Hat","lastmodified":"2006-08-30","contributor":"Mark J Cox","statementText":"This is not a security issue. The mod_usertrack cookies are not designed to be used for authentication.","cve_year":"2001","cve_id":"1534","crc32":"8a15f880"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:58:11.459Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"3521","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/3521"},{"name":"apache-modusertrack-predicticable-sessionid(7494)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/7494.php"},{"name":"20011113 Brute-Forcing Web Application Session IDs","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00084.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-07-14T04:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"3521","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/3521"},{"name":"apache-modusertrack-predicticable-sessionid(7494)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/7494.php"},{"name":"20011113 Brute-Forcing Web Application Session IDs","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00084.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-1534","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"3521","refsource":"BID","url":"http://www.securityfocus.com/bid/3521"},{"name":"apache-modusertrack-predicticable-sessionid(7494)","refsource":"XF","url":"http://www.iss.net/security_center/static/7494.php"},{"name":"20011113 Brute-Forcing Web Application Session IDs","refsource":"BUGTRAQ","url":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00084.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-1534","datePublished":"2005-07-14T04:00:00.000Z","dateReserved":"2005-07-14T00:00:00.000Z","dateUpdated":"2024-09-17T03:27:53.707Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-384","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*","versionStartIncluding":"1.3.11","versionEndIncluding":"1.3.20","matchCriteriaId":"D967723E-8D18-4C07-BA5C-D484E68DCB11"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"1534","Ordinal":"1","Title":"CVE-2001-1534","CVE":"CVE-2001-1534","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"1534","Ordinal":"1","NoteData":"mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.","Type":"Description","Title":"CVE-2001-1534"},{"CveYear":"2001","CveId":"1534","Ordinal":"2","NoteData":"2005-07-14","Type":"Other","Title":"Published"}]}}}