CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
404 vulnerabilities with CWE-384
CVE-2019-13517
HIGH
Pyxis ES <1.6.1 - Privilege Escalation
CVSS 8.8
CVE-2019-12258
HIGH
URGENT/11 Scanner, Based on Detection Tool by Armis
CVSS 7.5
CVE-2019-5406
HIGH
HPE 3PAR StoreServ Management Console < 3.5.0.1 - Remote Session Reuse
CVSS 7.2
CVE-2019-5400
MEDIUM
HPE 3PAR Service Processor <5.0.5.1 - SSRF
CVSS 6.3
CVE-2019-10371
HIGH
Jenkins Gitlab Auth Plugin <1.4 - Privilege Escalation
CVSS 7.5
CVE-2019-7849
HIGH
Magento <1.9.4.2, <1.14.4.2, <2.1.18, <2.2.9, <2.3.2 - Info Disclosure
CVSS 7.5
CVE-2019-4439
MEDIUM
IBM Cloud Private <3.1.2 - Privilege Escalation
CVSS 5.3
CVE-2019-10120
HIGH
eQ-3 HomeMatic CCU2/CCU3 <2.41.8/<3.43.16 - Auth Bypass
CVSS 8.8
CVE-2019-4152
MEDIUM
IBM Security Access Manager <9.0.7 - Info Disclosure
CVSS 4.4
CVE-2019-6584
HIGH
SIEMENS LOGO!8 - Privilege Escalation
CVSS 8.8
CVE-2019-10045
MEDIUM
Pydio < 8.2.2 - Session Fixation via Session Cookie Disclosure
CVSS 6.5
CVE-2019-1807
HIGH
Cisco Umbrella Dashboard - Privilege Escalation
CVSS 7.6
CVE-2019-10008
HIGH
Zoho ManageEngine ServiceDesk 9.3 - Privilege Escalation
CVSS 8.8
CVE-2019-11213
HIGH
Pulse Secure <5.3R7, <9.0R3 - Privilege Escalation
CVSS 8.1
CVE-2019-5523
CRITICAL
VMware vCloud Director for Service Providers <9.5.0.3 - RCE
CVSS 9.8
CVE-2019-9744
HIGH
PHOENIX CONTACT FL NAT SMCS/SMN - Auth Bypass
CVSS 8.8
CVE-2019-3784
HIGH
Cloud Foundry Stratos <2.3.0 - Privilege Escalation
CVSS 8.2
CVE-2019-3783
HIGH
Cloud Foundry Stratos <2.3.0 - Privilege Escalation
CVSS 8.8
CVE-2019-0102
HIGH
Intel(R) Data Center Manager SDK <5.0.2 - Privilege Escalation
CVSS 8.8
CVE-2019-7747
CRITICAL
DbNinja 3.2.7 - Session Fixation via data.php sessid Parameter
CVSS 9.6
CVE-2019-1003019
MEDIUM
Jenkins GitHub Auth Plug <0.29 - Privilege Escalation
CVSS 5.9
CVE-2019-7350
HIGH
ZoneMinder <1.32.3 - Session Fixation
CVSS 7.3
CVE-2018-16495
HIGH
Versa Operating System < 16.1r2s11 - Session Fixation via Pre-Authentication Token
CVSS 8.8
CVE-2018-15208
HIGH
BPC SmartVista 2 - Session Fixation via JSESSIONID Parameter
CVSS 7.5
CVE-2018-1626
LOW
IBM Security Privileged Identity Manager Virtual Appliance <2.2.1 -...
CVSS 3.1
Details
Vulnerabilities
404