CWE-384

Session Fixation

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

392 vulnerabilities with CWE-384
CVE-2020-15018 MEDIUM
playSMS <1.4.3 - Session Fixation
CVSS 6.5
CVE-2020-4229 HIGH
IBM Worklight/MobileFoundation 8.0.0.0 - Privilege Escalation
CVSS 7.3
CVE-2020-13229 HIGH
Sysax Multi Server 6.90 - Info Disclosure
CVSS 8.8
CVE-2020-8434 CRITICAL
Jenzabar JICS <9.0.1-9.2.2 - Info Disclosure
CVSS 9.8
CVE-2020-12258 CRITICAL
rConfig 3.9.4 - Session Fixation
CVSS 9.1
CVE-2020-1993 LOW
PAN-OS <8.1.14, <9.0.8 - Session Fixation
CVSS 3.7
CVE-2020-5894 HIGH
NGINX Controller <3.3.0 - Info Disclosure
CVSS 8.1
CVE-2020-12467 MEDIUM
Subrion CMS 4.2.1 - Session Fixation
CVSS 6.5
CVE-2020-1762 HIGH
Kiali <1.15.0 - Auth Bypass
CVSS 7.0
CVE-2020-6824 LOW
Firefox < 75 - Info Disclosure
CVSS 2.8
CVE-2020-11729 CRITICAL
DAViCal AWL <0.60 - Info Disclosure
CVSS 9.8
CVE-2020-11728 HIGH
DAViCal AWL <0.60 - Info Disclosure
CVSS 7.5
CVE-2020-8826 HIGH
Argo <1.5.0 - Info Disclosure
CVSS 7.5
CVE-2020-4291 MEDIUM
IBM Security Information Queue <1.0.6 - Info Disclosure
CVSS 4.3
CVE-2020-5550 HIGH
EasyBlocks IPv6 <2.0.1 & Enterprise <2.0.1 - Privilege Escalation
CVSS 8.1
CVE-2020-5290 MEDIUM
Ctfd Rctf < 2.3 - XSS
CVSS 6.5
CVE-2020-5543 CRITICAL
Mitsubishi Electric MELQIC IU1 <1.0.7 - DoS
CVSS 9.8
CVE-2020-9370 CRITICAL
HUMAX HGA12R-02 BRGCAA 1.1.53 - SSRF
CVSS 9.1
CVE-2020-8990 CRITICAL
Western Digital My Cloud Home <3.6.0 - SSRF
CVSS 9.1
CVE-2020-5205 MEDIUM
Pow <1.0.16 - Session Fixation
CVSS 6.5
CVE-2019-18946 MEDIUM
Micro Focus Solutions Business Manager Application Repository <11.7...
CVSS 4.8
CVE-2019-4563 MEDIUM
IBM Security Directory Server 6.4.0 - Open Redirect
CVSS 5.3
CVE-2019-4591 HIGH
IBM Maximo Asset Mgmt <7.6.1 - Privilege Escalation
CVSS 7.8
CVE-2019-19610 MEDIUM
Halvotec RaQuest <10.23.10801.0 - Session Fixation
CVSS 5.4
CVE-2019-4617 MEDIUM
IBM Cloud Automation Manager <3.2.1.0 - Info Disclosure
CVSS 4.4
Details
Vulnerabilities 392