mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
https://github.com/VitorRMNeto/port-scanner-cve-analyzer
https://httpd.apache.org/security/vulnerabilities_24.html
https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2199
http://www.apache.org/dist/httpd/CHANGES_2.4.6
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-2249
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698