CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
404 vulnerabilities with CWE-384
CVE-2020-25198
HIGH
MOXA NPort IAW5000A-I/O <2.1 - Session Fixation
CVSS 8.8
CVE-2020-4555
MEDIUM
IBM Financial Transaction Manager <3.1.0 - Privilege Escalation
CVSS 5.4
CVE-2020-5645
HIGH
GT14 GOT 1000 series - Info Disclosure
CVSS 7.5
CVE-2020-5654
HIGH
MELSEC iQ-R Series Firmware - Unauthenticated Session Fixation via TCP/IP Function
CVSS 7.5
CVE-2020-15909
HIGH
SolarWinds N-central <2020.1 - Session Hijacking
CVSS 8.8
CVE-2020-10714
HIGH
WildFly Elytron <1.11.3.Final - Privilege Escalation
CVSS 7.5
CVE-2020-6302
HIGH
SAP Commerce <2005 - Session Fixation
CVSS 8.1
CVE-2020-4243
LOW
IBM Security Identity Governance and Intelligence <5.2.6 - Info Dis...
CVSS 3.7
CVE-2020-4527
MEDIUM
IBM Planning Analytics 2.0 - Info Disclosure
CVSS 5.9
CVE-2020-6290
MEDIUM
SAP Disclosure Mgmt <10.1 - Session Fixation
CVSS 6.3
CVE-2020-5596
HIGH
Mitsubishi Electric GOT2000 CoreOS -Y - Session Fixation via Crafted Packet
CVSS 7.5
CVE-2020-15018
MEDIUM
playSMS <= 1.4.3 - Session Fixation
CVSS 6.5
CVE-2020-4229
HIGH
IBM Worklight/MobileFoundation 8.0.0.0 - Privilege Escalation
CVSS 7.3
CVE-2020-13229
HIGH
Sysax Multi Server 6.90 - Info Disclosure
CVSS 8.8
CVE-2020-8434
CRITICAL
Jenzabar JICS <9.0.1-9.2.2 - Info Disclosure
CVSS 9.8
CVE-2020-12258
CRITICAL
rConfig 3.9.4 - Session Fixation via PHPSESSID
CVSS 9.1
CVE-2020-1993
LOW
PAN-OS <8.1.14, <9.0.8 - Session Fixation
CVSS 3.7
CVE-2020-5894
HIGH
NGINX Controller <3.3.0 - Info Disclosure
CVSS 8.1
CVE-2020-12467
MEDIUM
Subrion CMS 4.2.1 - Session Fixation
CVSS 6.5
CVE-2020-1762
HIGH
Kiali 0.4.0-1.15.0 - Insufficient Session Expiration via JWT Validation Bypass
CVSS 7.0
CVE-2020-6824
LOW
Firefox < 75.0 - Session Fixation via Password Generation in Private Browsing Mode
CVSS 2.8
CVE-2020-11729
CRITICAL
DAViCal AWL <0.60 - Info Disclosure
CVSS 9.8
CVE-2020-11728
HIGH
DAViCal AWL <0.60 - Info Disclosure
CVSS 7.5
CVE-2020-8826
HIGH
Argo CD < 1.5.0 - Session Fixation via Immutable Authentication Tokens
CVSS 7.5
CVE-2020-4291
MEDIUM
IBM Security Information Queue <1.0.6 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities
404