CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
416 vulnerabilities with CWE-384
CVE-2018-10591
MEDIUM
Advantech WebAccess <8.2_20170817, Dashboard <2.0.15, Scada Node <8.3.1, NMS <2.0.3 - Origin Validation Error
CVSS 6.1
CVE-2018-10252
HIGH
Actiontec WCB6200Q <1.1.10.20a - Session Hijacking
CVSS 8.1
CVE-2018-1000173
MEDIUM
Jenkins Google Login Plugin <1.3 - Privilege Escalation
CVSS 5.9
CVE-2018-0564
HIGH
EC-CUBE 3.0.0-3.0.15 - Session Fixation
CVSS 8.1
CVE-2018-0229
MEDIUM
Cisco AnyConnect Secure Mobility Client and Adaptive Security Appliance - Session Fixation via SAML SSO Authentication
CVSS 6.5
CVE-2018-6959
CRITICAL
VMware vRA <7.4.0 - Privilege Escalation
CVSS 9.8
CVE-2018-2409
MEDIUM
SAP Cloud Platform 2.0 - Info Disclosure
CVSS 6.3
CVE-2018-2408
HIGH
SAP Business Objects <4.10-4.30 - Privilege Escalation
CVSS 7.3
CVE-2018-5465
HIGH
Belden Hirschmann - Session Fixation
CVSS 8.8
CVE-2017-12619
HIGH
Apache Zeppelin <0.7.3 - Info Disclosure
CVSS 8.1
CVE-2017-18105
HIGH
Atlassian Crowd <3.0.2, >3.1.0-<3.1.1 - Session Fixation
CVSS 8.1
CVE-2017-1368
MEDIUM
IBM Security Identity Governance Virtual Appliance <5.2.3.2 - Open ...
CVSS 4.3
CVE-2017-3968
HIGH
McAfee NSM <8.2.7.42.2, NDLP <9.3.4.1.5 - Info Disclosure
CVSS 7.5
CVE-2017-18125
HIGH
Android <2018-04-05 - Info Disclosure
CVSS 7.5
CVE-2017-1270
LOW
IBM Security Guardium 10.0 - Info Disclosure
CVSS 3.3
CVE-2017-11562
HIGH
MT4 Networks SenhaSegura Web App <2.2.23.8 - Info Disclosure
CVSS 8.8
CVE-2017-10890
MEDIUM
RX-V200 <09.87.17.09 - Info Disclosure
CVSS 4.6
CVE-2017-1000150
HIGH
Mahara <15.04.7, <15.10.3 - Info Disclosure
CVSS 8.8
CVE-2017-14163
HIGH
Mahara <15.04.14,16.x<16.04.8,16.10.x<16.10.5,17.x<17.04.3 - Info D...
CVSS 8.8
CVE-2017-15304
CRITICAL
Airtame HDMI Dongle Firmware < 2.3.3 - Session Fixation via PHPSESSID Cookie
CVSS 9.8
CVE-2017-11191
HIGH
FreeIPA 4.x - Authenticated Session Fixation via Old Session ID
CVSS 8.8
CVE-2017-14263
HIGH
Honeywell Enterprise DVR and MaxPro NVR Firmware - Session Fixation via Guest Account Session ID
CVSS 8.1
CVE-2017-12225
MEDIUM
Cisco Prime LAN Management Solution - Session Fixation
CVSS 6.5
CVE-2017-12873
CRITICAL
SimpleSAMLphp <1.14.10 - Info Disclosure
CVSS 9.8
CVE-2017-12868
CRITICAL
SimpleSAMLphp <1.14.13 - Session Fixation
CVSS 9.8
Details
Vulnerabilities
416