CWE-384

Session Fixation

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

416 vulnerabilities with CWE-384
CVE-2017-12965 CRITICAL
Apache2Triad 1.5.4 - Info Disclosure
CVSS 9.8
CVE-2017-10600 MEDIUM
ubuntu-image <2017-07-07 - Info Disclosure
CVSS 5.9
CVE-2017-2145 MEDIUM
Cybozu Garoon <4.2.4 - Info Disclosure
CVSS 5.4
CVE-2017-4963 HIGH
Cloud Foundry Foundation Cloud Foundry <v252 - Session Fixation
CVSS 8.1
CVE-2017-4014 HIGH
McAfee Network Data Loss Prevention 9.3.x - Authenticated Session Fixation via HTTP Request Modification
CVSS 8.0
CVE-2017-0892 LOW
Nextcloud Server <11.0.3 - Info Disclosure
CVSS 3.5
CVE-2017-5656 HIGH
Apache CXF <3.1.11, <3.0.13 - Privilege Escalation
CVSS 7.5
CVE-2017-1152 MEDIUM
IBM Financial Transaction Manager <3.0.2 - Info Disclosure
CVSS 4.3
CVE-2017-6412 HIGH
Sophos Web Appliance <4.3.1.2 - Session Fixation
CVSS 8.1
CVE-2017-5831 MEDIUM
Revive Adserver <4.0.1 - Info Disclosure
CVSS 5.9
CVE-2017-5141 MEDIUM
Honeywell XL Web II controller <XL1000C500 - Session Fixation
CVSS 6.0
CVE-2016-8609 LOW
Keycloak < 2.3.0 - Improper Authentication via Phishing URL
CVSS 3.7
CVE-2016-9574 MEDIUM
Network Security Services < 3.30 - Denial of Service via SessionTicket Extension
CVSS 5.9
CVE-2016-6545 CRITICAL
iTrack Easy - Info Disclosure
CVSS 9.8
CVE-2016-10405 CRITICAL
D-Link DIR-600L <FW1.17.B01 - Info Disclosure
CVSS 9.8
CVE-2016-9981 HIGH
IBM AppScan Enterprise Edition 9.0 - Auth Bypass
CVSS 8.1
CVE-2016-8638 CRITICAL
ipsilon <2.0.2,1.2.1,1.1.2,1.0.3 - Info Disclosure
CVSS 9.1
CVE-2016-0721 HIGH
pcs < 0.9.157 - Session Fixation
CVSS 8.1
CVE-2016-9125 CRITICAL
Revive Adserver <3.2.3 - Session Fixation
CVSS 9.8
CVE-2016-10205 HIGH
ZoneMinder < 1.30.0 - Session Fixation via ZMSESSID Cookie
CVSS 7.3
CVE-2016-9703 LOW
IBM Security Identity Manager Virtual Appliance - Info Disclosure
CVSS 2.4
CVE-2016-6043 HIGH
Tivoli Storage Manager Operations Center - Privilege Escalation
CVSS 7.0
CVE-2016-6040 MEDIUM
IBM Jazz Foundation - Privilege Escalation
CVSS 5.0
CVE-2015-5384 HIGH
AxiomSL's Axiom Google Web Toolkit <9.5.3 - SSRF
CVSS 8.8
CVE-2015-1820 CRITICAL
REST client <1.8.0 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 416