Versions of Jetty, the popular java web server, are vulnerable to a session id prediction attack. Jetty uses java.util.Random to generate session ids. The internal state of this generator can be easily discovered, leading to an attacker being able to hijack existing and future sessions. Jetty versions below 4.2.27, 5.1.12, 6.0.2 and 6.1.0pre3 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/54206/NGS00471.txt
Source: https://packetstormsecurity.com/files/54206/NGS00471.txt.html

