The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs.
CVSS Metrics