CWE-384

Session Fixation

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

392 vulnerabilities with CWE-384
CVE-2021-39290 CRITICAL
NetModule <4.3.0.113-4.5.0.105 - Limited Session Fixation
CVSS 9.8
CVE-2021-22927 HIGH
Citrix ADC/Gateway <13.0-82.45 - Session Fixation
CVSS 8.1
CVE-2021-2351 HIGH
Oracle Database Server <19c - Info Disclosure
CVSS 8.3
CVE-2021-32710 MEDIUM
Shopware <6.3.5.2 - Info Disclosure
CVSS 5.9
CVE-2021-35046 MEDIUM
Ice Hrm 29.0.0 - Info Disclosure
CVSS 6.1
CVE-2021-32676 MEDIUM
Nextcloud Talk <9.0.10, 10.0.8, 11.2.2 - Info Disclosure
CVSS 6.5
CVE-2021-33394 MEDIUM
Cubecart 6.4.2 - Session Fixation
CVSS 5.4
CVE-2020-36913 MEDIUM
All-Dynamics Software enlogic:show 2.0.2 - CSRF
CVSS 5.3
CVE-2020-15679 HIGH
Mozilla VPN <1.2.2 - Session Fixation
CVSS 7.6
CVE-2020-25152 MEDIUM
B. Braun Melsungen AG - Session Fixation
CVSS 6.5
CVE-2020-35229 HIGH
NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 - Privilege Escalation
CVSS 8.8
CVE-2020-35591 MEDIUM
Pi-hole 5.0-5.1.1 - Session Fixation
CVSS 5.4
CVE-2020-4954 MEDIUM
IBM Spectrum Protect Operations Center <8.1 - Auth Bypass
CVSS 5.4
CVE-2020-5021 MEDIUM
IBM Spectrum Protect Plus <10.1.7 - Privilege Escalation
CVSS 4.4
CVE-2020-25198 HIGH
MOXA NPort IAW5000A-I/O <2.1 - Session Fixation
CVSS 8.8
CVE-2020-4555 MEDIUM
IBM Financial Transaction Manager <3.1.0 - Privilege Escalation
CVSS 5.4
CVE-2020-5645 HIGH
GT14 GOT 1000 series - Info Disclosure
CVSS 7.5
CVE-2020-5654 HIGH
MELSEC iQ-R - Session Fixation
CVSS 7.5
CVE-2020-15909 HIGH
SolarWinds N-central <2020.1 - Session Hijacking
CVSS 8.8
CVE-2020-10714 HIGH
WildFly Elytron <1.11.3.Final - Privilege Escalation
CVSS 7.5
CVE-2020-6302 HIGH
SAP Commerce <2005 - Session Fixation
CVSS 8.1
CVE-2020-4243 LOW
IBM Security Identity Governance and Intelligence <5.2.6 - Info Dis...
CVSS 3.7
CVE-2020-4527 MEDIUM
IBM Planning Analytics 2.0 - Info Disclosure
CVSS 5.9
CVE-2020-6290 MEDIUM
SAP Disclosure Mgmt <10.1 - Session Fixation
CVSS 6.3
CVE-2020-5596 HIGH
Mitsubishi Electric GOT2000 - DoS
CVSS 7.5
Details
Vulnerabilities 392