CWE-384

Session Fixation

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

416 vulnerabilities with CWE-384
CVE-2018-18925 CRITICAL
Gogs < 0.11.66 - Remote Code Execution via Session File Forgery
CVSS 9.8
CVE-2018-13282 MEDIUM
Synology Photo Station <6.8.7-3481 - Info Disclosure
CVSS 5.6
CVE-2018-16463 LOW
Nextcloud Server <14.0.0-12.0.8 - Info Disclosure
CVSS 3.1
CVE-2018-18380 MEDIUM
BigTree CMS < 4.2.24 - Session Fixation via admin.php
CVSS 5.4
CVE-2018-17902 MEDIUM
Yokogawa STARDOM Controllers FCJ FCN-100 FCN-RTU FCN-500 < R4.10 - Denial of Service via Session Management
CVSS 5.3
CVE-2018-9082 HIGH
Iomega LenovoEMC NAS <4.1.402.34662 - Privilege Escalation
CVSS 8.8
CVE-2018-8852 HIGH
Philips e-Alert Unit <R2.1 - Info Disclosure
CVSS 8.8
CVE-2018-1127 MEDIUM
Red Hat Gluster Storage <3.4.0 - Info Disclosure
CVSS 4.2
CVE-2018-5385 HIGH
Navarino Infinity - Session Fixation
CVSS 8.8
CVE-2018-14387 HIGH
WonderCMS < 2.5.2 - Session Fixation
CVSS 8.8
CVE-2018-1492 MEDIUM
IBM Jazz Foundation - Privilege Escalation
CVSS 4.3
CVE-2018-1000602 MEDIUM
Jenkins SAML Plugin <1.0.6 - Privilege Escalation
CVSS 5.9
CVE-2018-1000519 MEDIUM
aio-libs aiohttp-session - Session Fixation
CVSS 6.5
CVE-2018-12538 HIGH
Eclipse Jetty <9.4.8 - Privilege Escalation
CVSS 8.8
CVE-2018-0359 MEDIUM
Cisco Meeting Server - Session Fixation
CVSS 5.5
CVE-2018-9026 HIGH
CA Privileged Access Manager 2.x - Session Fixation
CVSS 7.5
CVE-2018-12071 CRITICAL
CodeIgniter <3.1.9 - Info Disclosure
CVSS 9.8
CVE-2018-11385 HIGH
Symfony Security 2.7.0-2.7.47 - Session Fixation via Guard Login Feature
CVSS 8.1
CVE-2018-11714 CRITICAL
TP-Link TL-WR840N/TL-WR841N <5 - Info Disclosure
CVSS 9.8
CVE-2018-11571 HIGH
ClipperCMS 1.3.3 - Session Fixation
CVSS 8.8
CVE-2018-11567 LOW
Amazon Echo <2018-04-27 - Info Disclosure
CVSS 3.3
CVE-2018-1375 MEDIUM
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 - Session ...
CVSS 5.9
CVE-2018-11475 HIGH
Monstra CMS 3.0.4 - Info Disclosure
CVSS 8.0
CVE-2018-11474 HIGH
Monstra CMS 3.0.4 - Info Disclosure
CVSS 8.0
CVE-2018-1148 MEDIUM
Nessus <7.1.0 - Privilege Escalation
CVSS 6.5
Details
Vulnerabilities 416