CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

576 vulnerabilities with CWE-613
CVE-2019-5531 MEDIUM
VMware ESXi and vCenter Server - Insufficient Session Expiration
CVSS 5.4
CVE-2019-14826 MEDIUM
FreeIPA >= 4.5.0 - Insufficient Session Expiration
CVSS 4.4
CVE-2019-16133 MEDIUM
Eteams OA <4.0.34 - Info Disclosure
CVSS 6.5
CVE-2019-5638 HIGH
Rapid7 Nexpose <= 6.5.50 - Insufficient Session Expiration
CVSS 8.7
CVE-2019-2386 HIGH
MongoDB Server <4.0.9, <3.6.13, <3.4.22 - Info Disclosure
CVSS 7.1
CVE-2019-7280 HIGH
Prima Systems FlexAir <2.3.38 - Info Disclosure
CVSS 8.8
CVE-2019-6584 HIGH
SIEMENS LOGO!8 - Privilege Escalation
CVSS 8.8
CVE-2019-3790 MEDIUM
Pivotal Ops Manager Authenticated Session Fixation via Refresh Token Bypass
CVSS 6.1
CVE-2019-7215 MEDIUM
Progress Sitefinity 10.1.6536 - Info Disclosure
CVSS 6.5
CVE-2019-4072 MEDIUM
IBM Spectrum Control 5.2.1-5.2.17 - Insufficient Session Expiration
CVSS 6.3
CVE-2019-1003049 HIGH
Jenkins < 2.164.1 and < 2.171 - Insufficient Session Expiration
CVSS 8.1
CVE-2019-0015 MEDIUM
Junos OS on SRX Series Insufficient Session Expiration
CVSS 5.4
CVE-2018-21018 CRITICAL
Mastodon < 2.6.3 - Insufficient Session Expiration
CVSS 9.8
CVE-2018-6634 CRITICAL
Parsec Windows 142-0 and Linux Ubuntu 16.04 LTS Desktop Build 142-1 - Insufficient Session Expiration
CVSS 9.8
CVE-2018-1000814 MEDIUM
aio-libs aiohttp-session <=2.6.0 - Non-Expiring Sessions
CVSS 6.5
CVE-2018-1127 MEDIUM
Red Hat Gluster Storage <3.4.0 - Info Disclosure
CVSS 4.2
CVE-2018-2451 MEDIUM
SAP HANA Extended Application Services - Insufficient Session Expiration
CVSS 6.6
CVE-2018-14345 HIGH
SDDM <0.17.0 - Privilege Escalation
CVSS 7.5
CVE-2018-11386 MEDIUM
Symfony HttpFoundation 2.7.0-2.7.47 - Denial of Service via PDOSessionHandler
CVSS 5.9
CVE-2018-10990 HIGH
Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 - Insufficient Session Expiration
CVSS 8.0
CVE-2018-7758 MEDIUM
Schneider Electric's MiCOM Px4x - DoS
CVSS 6.5
CVE-2018-0152 HIGH
Cisco IOS XE - Insufficient Session Expiration in Web UI
CVSS 8.8
CVE-2018-5438 MEDIUM
Philips ISCV <2.3.0 - Privilege Escalation
CVSS 6.3
CVE-2018-1195 HIGH
Cloud Controller <1.46.0 - Auth Bypass
CVSS 8.8
CVE-2017-18905 MEDIUM
Mattermost Server <4.0.0-3.9.2 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 576