CWE-384

Session Fixation

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

404 vulnerabilities with CWE-384
CVE-2020-5550 HIGH
EasyBlocks IPv6 <2.0.1 & Enterprise <2.0.1 - Privilege Escalation
CVSS 8.1
CVE-2020-5290 MEDIUM
Ctfd Rctf < 2.3 - XSS
CVSS 6.5
CVE-2020-5543 CRITICAL
Mitsubishi Electric MELQIC IU1 <1.0.7 - DoS
CVSS 9.8
CVE-2020-9370 CRITICAL
HUMAX HGA12R-02 BRGCAA 1.1.53 - SSRF
CVSS 9.1
CVE-2020-8990 CRITICAL
Western Digital My Cloud Home <3.6.0 - SSRF
CVSS 9.1
CVE-2020-5205 MEDIUM
Pow < 1.0.16 - Session Fixation via Persistent Session Store
CVSS 6.5
CVE-2019-18946 MEDIUM
Micro Focus Solutions Business Manager Application Repository <11.7...
CVSS 4.8
CVE-2019-4563 MEDIUM
IBM Security Directory Server 6.4.0 - Open Redirect
CVSS 5.3
CVE-2019-4591 HIGH
IBM Maximo Asset Mgmt <7.6.1 - Privilege Escalation
CVSS 7.8
CVE-2019-19610 MEDIUM
Halvotec RaQuest <10.23.10801.0 - Session Fixation
CVSS 5.4
CVE-2019-4617 MEDIUM
IBM Cloud Automation Manager <3.2.1.0 - Info Disclosure
CVSS 4.4
CVE-2019-15612 MEDIUM
Nextcloud Server <15.0.2 - Info Disclosure
CVSS 5.9
CVE-2019-10158 CRITICAL
Infinispan <9.4.14.Final - Info Disclosure
CVSS 9.8
CVE-2019-17563 HIGH
Apache Tomcat <9.0.29, 8.5.49, 7.0.98 - Session Fixation
CVSS 7.5
CVE-2019-18573 HIGH
RSA Identity Governance <7.1.1 P03 - Session Fixation
CVSS 8.8
CVE-2019-8116 HIGH
Magento <2.2.10-2.3.3/2.3.2-p1 - Auth Bypass
CVSS 7.5
CVE-2019-10084 HIGH
Apache Impala 2.7.0-3.2.0 - Auth Bypass
CVSS 7.5
CVE-2019-17062 HIGH
OXID eShop <6.0.6/<6.1.5 - Privilege Escalation
CVSS 8.8
CVE-2019-18418 CRITICAL
ClonOS WEB control panel 19.09 - RCE
CVSS 9.8
CVE-2019-15849 HIGH
eQ-3 HomeMatic CCU3 firmware 3.41.11 - Session Fixation
CVSS 7.3
CVE-2019-0062 HIGH
Junos OS <12.3R12-S15 - Session Fixation
CVSS 7.5
CVE-2019-4227 HIGH
IBM MQ 8.0.0.4-8.0.0.12, 9.0.0.0-9.0.0.6, 9.1.0.0-9.1.0.2, 9.1.0-9.1.2 - Session Fixation via AMQP Listener
CVSS 7.3
CVE-2019-4304 MEDIUM
IBM WebSphere Application Server - Liberty - Auth Bypass
CVSS 6.3
CVE-2019-6161 HIGH
ThinkAgile CP-SB <1908.M - Info Disclosure
CVSS 7.5
CVE-2019-12203 MEDIUM
SilverStripe <4.3.3 - Info Disclosure
CVSS 6.3
Details
Vulnerabilities 404