CWE-384

Session Fixation

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

416 vulnerabilities with CWE-384
CVE-2019-17563 HIGH
Apache Tomcat <9.0.29, 8.5.49, 7.0.98 - Session Fixation
CVSS 7.5
CVE-2019-18573 HIGH
RSA Identity Governance <7.1.1 P03 - Session Fixation
CVSS 8.8
CVE-2019-8116 HIGH
Magento <2.2.10-2.3.3/2.3.2-p1 - Auth Bypass
CVSS 7.5
CVE-2019-10084 HIGH
Apache Impala 2.7.0-3.2.0 - Auth Bypass
CVSS 7.5
CVE-2019-17062 HIGH
OXID eShop <6.0.6/<6.1.5 - Privilege Escalation
CVSS 8.8
CVE-2019-18418 CRITICAL
ClonOS WEB control panel 19.09 - RCE
CVSS 9.8
CVE-2019-15849 HIGH
eQ-3 HomeMatic CCU3 firmware 3.41.11 - Session Fixation
CVSS 7.3
CVE-2019-0062 HIGH
Junos OS <12.3R12-S15 - Session Fixation
CVSS 7.5
CVE-2019-4227 HIGH
IBM MQ 8.0.0.4-8.0.0.12, 9.0.0.0-9.0.0.6, 9.1.0.0-9.1.0.2, 9.1.0-9.1.2 - Session Fixation via AMQP Listener
CVSS 7.3
CVE-2019-4304 MEDIUM
IBM WebSphere Application Server - Liberty - Auth Bypass
CVSS 6.3
CVE-2019-6161 HIGH
ThinkAgile CP-SB <1908.M - Info Disclosure
CVSS 7.5
CVE-2019-12203 MEDIUM
SilverStripe <4.3.3 - Info Disclosure
CVSS 6.3
CVE-2019-13517 HIGH
Pyxis ES <1.6.1 - Privilege Escalation
CVSS 8.8
CVE-2019-12258 HIGH
URGENT/11 Scanner, Based on Detection Tool by Armis
CVSS 7.5
CVE-2019-5406 HIGH
HPE 3PAR StoreServ Management Console < 3.5.0.1 - Remote Session Reuse
CVSS 7.2
CVE-2019-5400 MEDIUM
HPE 3PAR Service Processor <5.0.5.1 - SSRF
CVSS 6.3
CVE-2019-10371 HIGH
Jenkins Gitlab Auth Plugin <1.4 - Privilege Escalation
CVSS 7.5
CVE-2019-7849 HIGH
Magento <1.9.4.2, <1.14.4.2, <2.1.18, <2.2.9, <2.3.2 - Info Disclosure
CVSS 7.5
CVE-2019-4439 MEDIUM
IBM Cloud Private <3.1.2 - Privilege Escalation
CVSS 5.3
CVE-2019-10120 HIGH
eQ-3 HomeMatic CCU2/CCU3 <2.41.8/<3.43.16 - Auth Bypass
CVSS 8.8
CVE-2019-4152 MEDIUM
IBM Security Access Manager <9.0.7 - Info Disclosure
CVSS 4.4
CVE-2019-6584 HIGH
SIEMENS LOGO!8 - Privilege Escalation
CVSS 8.8
CVE-2019-10045 MEDIUM
Pydio < 8.2.2 - Session Fixation via Session Cookie Disclosure
CVSS 6.5
CVE-2019-1807 HIGH
Cisco Umbrella Dashboard - Privilege Escalation
CVSS 7.6
CVE-2019-10008 HIGH
Zoho ManageEngine ServiceDesk 9.3 - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 416