CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
416 vulnerabilities with CWE-384
CVE-2017-12965
CRITICAL
Apache2Triad 1.5.4 - Info Disclosure
CVSS 9.8
CVE-2017-10600
MEDIUM
ubuntu-image <2017-07-07 - Info Disclosure
CVSS 5.9
CVE-2017-2145
MEDIUM
Cybozu Garoon <4.2.4 - Info Disclosure
CVSS 5.4
CVE-2017-4963
HIGH
Cloud Foundry Foundation Cloud Foundry <v252 - Session Fixation
CVSS 8.1
CVE-2017-4014
HIGH
McAfee Network Data Loss Prevention 9.3.x - Authenticated Session Fixation via HTTP Request Modification
CVSS 8.0
CVE-2017-0892
LOW
Nextcloud Server <11.0.3 - Info Disclosure
CVSS 3.5
CVE-2017-5656
HIGH
Apache CXF <3.1.11, <3.0.13 - Privilege Escalation
CVSS 7.5
CVE-2017-1152
MEDIUM
IBM Financial Transaction Manager <3.0.2 - Info Disclosure
CVSS 4.3
CVE-2017-6412
HIGH
Sophos Web Appliance <4.3.1.2 - Session Fixation
CVSS 8.1
CVE-2017-5831
MEDIUM
Revive Adserver <4.0.1 - Info Disclosure
CVSS 5.9
CVE-2017-5141
MEDIUM
Honeywell XL Web II controller <XL1000C500 - Session Fixation
CVSS 6.0
CVE-2016-8609
LOW
Keycloak < 2.3.0 - Improper Authentication via Phishing URL
CVSS 3.7
CVE-2016-9574
MEDIUM
Network Security Services < 3.30 - Denial of Service via SessionTicket Extension
CVSS 5.9
CVE-2016-6545
CRITICAL
iTrack Easy - Info Disclosure
CVSS 9.8
CVE-2016-10405
CRITICAL
D-Link DIR-600L <FW1.17.B01 - Info Disclosure
CVSS 9.8
CVE-2016-9981
HIGH
IBM AppScan Enterprise Edition 9.0 - Auth Bypass
CVSS 8.1
CVE-2016-8638
CRITICAL
ipsilon <2.0.2,1.2.1,1.1.2,1.0.3 - Info Disclosure
CVSS 9.1
CVE-2016-0721
HIGH
pcs < 0.9.157 - Session Fixation
CVSS 8.1
CVE-2016-9125
CRITICAL
Revive Adserver <3.2.3 - Session Fixation
CVSS 9.8
CVE-2016-10205
HIGH
ZoneMinder < 1.30.0 - Session Fixation via ZMSESSID Cookie
CVSS 7.3
CVE-2016-9703
LOW
IBM Security Identity Manager Virtual Appliance - Info Disclosure
CVSS 2.4
CVE-2016-6043
HIGH
Tivoli Storage Manager Operations Center - Privilege Escalation
CVSS 7.0
CVE-2016-6040
MEDIUM
IBM Jazz Foundation - Privilege Escalation
CVSS 5.0
CVE-2015-5384
HIGH
AxiomSL's Axiom Google Web Toolkit <9.5.3 - SSRF
CVSS 8.8
CVE-2015-1820
CRITICAL
REST client <1.8.0 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities
416