CWE-384

Session Fixation

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

416 vulnerabilities with CWE-384
CVE-2019-11213 HIGH
Pulse Secure <5.3R7, <9.0R3 - Privilege Escalation
CVSS 8.1
CVE-2019-5523 CRITICAL
VMware vCloud Director for Service Providers <9.5.0.3 - RCE
CVSS 9.8
CVE-2019-9744 HIGH
PHOENIX CONTACT FL NAT SMCS/SMN - Auth Bypass
CVSS 8.8
CVE-2019-3784 HIGH
Cloud Foundry Stratos <2.3.0 - Privilege Escalation
CVSS 8.2
CVE-2019-3783 HIGH
Cloud Foundry Stratos <2.3.0 - Privilege Escalation
CVSS 8.8
CVE-2019-0102 HIGH
Intel(R) Data Center Manager SDK <5.0.2 - Privilege Escalation
CVSS 8.8
CVE-2019-7747 CRITICAL
DbNinja 3.2.7 - Session Fixation via data.php sessid Parameter
CVSS 9.6
CVE-2019-1003019 MEDIUM
Jenkins GitHub Auth Plug <0.29 - Privilege Escalation
CVSS 5.9
CVE-2019-7350 HIGH
ZoneMinder <1.32.3 - Session Fixation
CVSS 7.3
CVE-2018-16495 HIGH
Versa Operating System < 16.1r2s11 - Session Fixation via Pre-Authentication Token
CVSS 8.8
CVE-2018-15208 HIGH
BPC SmartVista 2 - Session Fixation via JSESSIONID Parameter
CVSS 7.5
CVE-2018-1626 LOW
IBM Security Privileged Identity Manager Virtual Appliance <2.2.1 -...
CVSS 3.1
CVE-2018-1948 MEDIUM
IBM Security Identity Governance and Intelligence <5.2.4.1 - Open R...
CVSS 4.3
CVE-2018-20238 HIGH
Atlassian Crowd <3.2.7, >3.3.0-<3.3.4 - Auth Bypass
CVSS 8.1
CVE-2018-1962 MEDIUM
IBM Security Identity Manager <7.0.1 - Info Disclosure
CVSS 4.0
CVE-2018-17199 HIGH
Apache HTTP Server <2.4.38 - Info Disclosure
CVSS 7.5
CVE-2018-1000409 MEDIUM
Jenkins < 2.138.1, < 2.145 - Session Fixation via User Signup
CVSS 5.4
CVE-2018-1804 LOW
IBM Security Access Manager Appliance <9.0.5.0 - Info Disclosure
CVSS 3.7
CVE-2018-1485 LOW
IBM BigFix Platform <9.2.14, <9.5.9 - Privilege Escalation
CVSS 3.1
CVE-2018-1484 LOW
IBM BigFix Platform <9.2.14, <9.5.9 - Open Redirect
CVSS 3.7
CVE-2018-1480 MEDIUM
IBM BigFix Platform <9.2.14, <9.5.9 - Info Disclosure
CVSS 4.0
CVE-2018-13337 MEDIUM
TerraMaster TOS <3.1.03 - Info Disclosure
CVSS 5.4
CVE-2018-19443 MEDIUM
Tryton 5.x <5.0.1 - Info Disclosure
CVSS 5.9
CVE-2018-6434 HIGH
Brocade Fabric OS <8.2.1-7.4.2d - Info Disclosure
CVSS 7.5
CVE-2018-18926 CRITICAL
Gitea < 1.5.4 - Remote Code Execution via Session ID Handling
CVSS 9.8
Details
Vulnerabilities 416