CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
404 vulnerabilities with CWE-384
CVE-2018-1948
MEDIUM
IBM Security Identity Governance and Intelligence <5.2.4.1 - Open R...
CVSS 4.3
CVE-2018-20238
HIGH
Atlassian Crowd <3.2.7, >3.3.0-<3.3.4 - Auth Bypass
CVSS 8.1
CVE-2018-1962
MEDIUM
IBM Security Identity Manager <7.0.1 - Info Disclosure
CVSS 4.0
CVE-2018-17199
HIGH
Apache HTTP Server <2.4.38 - Info Disclosure
CVSS 7.5
CVE-2018-1000409
MEDIUM
Jenkins < 2.138.1, < 2.145 - Session Fixation via User Signup
CVSS 5.4
CVE-2018-1804
LOW
IBM Security Access Manager Appliance <9.0.5.0 - Info Disclosure
CVSS 3.7
CVE-2018-1485
LOW
IBM BigFix Platform <9.2.14, <9.5.9 - Privilege Escalation
CVSS 3.1
CVE-2018-1484
LOW
IBM BigFix Platform <9.2.14, <9.5.9 - Open Redirect
CVSS 3.7
CVE-2018-1480
MEDIUM
IBM BigFix Platform <9.2.14, <9.5.9 - Info Disclosure
CVSS 4.0
CVE-2018-13337
MEDIUM
TerraMaster TOS <3.1.03 - Info Disclosure
CVSS 5.4
CVE-2018-19443
MEDIUM
Tryton 5.x <5.0.1 - Info Disclosure
CVSS 5.9
CVE-2018-6434
HIGH
Brocade Fabric OS <8.2.1-7.4.2d - Info Disclosure
CVSS 7.5
CVE-2018-18926
CRITICAL
Gitea < 1.5.4 - Remote Code Execution via Session ID Handling
CVSS 9.8
CVE-2018-18925
CRITICAL
Gogs < 0.11.66 - Remote Code Execution via Session File Forgery
CVSS 9.8
CVE-2018-13282
MEDIUM
Synology Photo Station <6.8.7-3481 - Info Disclosure
CVSS 5.6
CVE-2018-16463
LOW
Nextcloud Server <14.0.0-12.0.8 - Info Disclosure
CVSS 3.1
CVE-2018-18380
MEDIUM
BigTree CMS < 4.2.24 - Session Fixation via admin.php
CVSS 5.4
CVE-2018-17902
MEDIUM
Yokogawa STARDOM Controllers FCJ FCN-100 FCN-RTU FCN-500 < R4.10 - Denial of Service via Session Management
CVSS 5.3
CVE-2018-9082
HIGH
Iomega LenovoEMC NAS <4.1.402.34662 - Privilege Escalation
CVSS 8.8
CVE-2018-8852
HIGH
Philips e-Alert Unit <R2.1 - Info Disclosure
CVSS 8.8
CVE-2018-1127
MEDIUM
Red Hat Gluster Storage <3.4.0 - Info Disclosure
CVSS 4.2
CVE-2018-5385
HIGH
Navarino Infinity - Session Fixation
CVSS 8.8
CVE-2018-14387
HIGH
WonderCMS < 2.5.2 - Session Fixation
CVSS 8.8
CVE-2018-1492
MEDIUM
IBM Jazz Foundation - Privilege Escalation
CVSS 4.3
CVE-2018-1000602
MEDIUM
Jenkins SAML Plugin <1.0.6 - Privilege Escalation
CVSS 5.9
Details
Vulnerabilities
404