CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
404 vulnerabilities with CWE-384
CVE-2020-5550
HIGH
EasyBlocks IPv6 <2.0.1 & Enterprise <2.0.1 - Privilege Escalation
CVSS 8.1
CVE-2020-5290
MEDIUM
Ctfd Rctf < 2.3 - XSS
CVSS 6.5
CVE-2020-5543
CRITICAL
Mitsubishi Electric MELQIC IU1 <1.0.7 - DoS
CVSS 9.8
CVE-2020-9370
CRITICAL
HUMAX HGA12R-02 BRGCAA 1.1.53 - SSRF
CVSS 9.1
CVE-2020-8990
CRITICAL
Western Digital My Cloud Home <3.6.0 - SSRF
CVSS 9.1
CVE-2020-5205
MEDIUM
Pow < 1.0.16 - Session Fixation via Persistent Session Store
CVSS 6.5
CVE-2019-18946
MEDIUM
Micro Focus Solutions Business Manager Application Repository <11.7...
CVSS 4.8
CVE-2019-4563
MEDIUM
IBM Security Directory Server 6.4.0 - Open Redirect
CVSS 5.3
CVE-2019-4591
HIGH
IBM Maximo Asset Mgmt <7.6.1 - Privilege Escalation
CVSS 7.8
CVE-2019-19610
MEDIUM
Halvotec RaQuest <10.23.10801.0 - Session Fixation
CVSS 5.4
CVE-2019-4617
MEDIUM
IBM Cloud Automation Manager <3.2.1.0 - Info Disclosure
CVSS 4.4
CVE-2019-15612
MEDIUM
Nextcloud Server <15.0.2 - Info Disclosure
CVSS 5.9
CVE-2019-10158
CRITICAL
Infinispan <9.4.14.Final - Info Disclosure
CVSS 9.8
CVE-2019-17563
HIGH
Apache Tomcat <9.0.29, 8.5.49, 7.0.98 - Session Fixation
CVSS 7.5
CVE-2019-18573
HIGH
RSA Identity Governance <7.1.1 P03 - Session Fixation
CVSS 8.8
CVE-2019-8116
HIGH
Magento <2.2.10-2.3.3/2.3.2-p1 - Auth Bypass
CVSS 7.5
CVE-2019-10084
HIGH
Apache Impala 2.7.0-3.2.0 - Auth Bypass
CVSS 7.5
CVE-2019-17062
HIGH
OXID eShop <6.0.6/<6.1.5 - Privilege Escalation
CVSS 8.8
CVE-2019-18418
CRITICAL
ClonOS WEB control panel 19.09 - RCE
CVSS 9.8
CVE-2019-15849
HIGH
eQ-3 HomeMatic CCU3 firmware 3.41.11 - Session Fixation
CVSS 7.3
CVE-2019-0062
HIGH
Junos OS <12.3R12-S15 - Session Fixation
CVSS 7.5
CVE-2019-4227
HIGH
IBM MQ 8.0.0.4-8.0.0.12, 9.0.0.0-9.0.0.6, 9.1.0.0-9.1.0.2, 9.1.0-9.1.2 - Session Fixation via AMQP Listener
CVSS 7.3
CVE-2019-4304
MEDIUM
IBM WebSphere Application Server - Liberty - Auth Bypass
CVSS 6.3
CVE-2019-6161
HIGH
ThinkAgile CP-SB <1908.M - Info Disclosure
CVSS 7.5
CVE-2019-12203
MEDIUM
SilverStripe <4.3.3 - Info Disclosure
CVSS 6.3
Details
Vulnerabilities
404