Vulnerabilities > Insufficient Session Expiration

DATE CVE VULNERABILITY TITLE RISK
2021-01-01 CVE-2016-20007 Insufficient Session Expiration vulnerability in Rest/Json Project Rest/Json
The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033.
network
low complexity
rest-json-project CWE-613
7.5
2020-12-10 CVE-2020-29667 Insufficient Session Expiration vulnerability in Lanatmservice M3 ATM Monitoring System 6.1.0
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.
network
low complexity
lanatmservice CWE-613
critical
9.8
2020-11-30 CVE-2020-4696 Insufficient Session Expiration vulnerability in IBM Cloud PAK for Security 1.3.0.1
IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow an authenticated user to obtain sensitive information from the previous session.
network
low complexity
ibm CWE-613
4.3
2020-11-17 CVE-2020-13353 Insufficient Session Expiration vulnerability in Gitlab Gitaly
When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.
local
low complexity
gitlab CWE-613
3.2
2020-11-16 CVE-2020-27422 Insufficient Session Expiration vulnerability in Anuko Time Tracker
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.
network
low complexity
anuko CWE-613
critical
9.8
2020-11-09 CVE-2020-23140 Insufficient Session Expiration vulnerability in Microweber 1.1.18
Microweber 1.1.18 is affected by insufficient session expiration.
network
low complexity
microweber CWE-613
8.1
2020-11-09 CVE-2020-23136 Insufficient Session Expiration vulnerability in Microweber 1.1.18
Microweber v1.1.18 is affected by no session expiry after log-out.
local
low complexity
microweber CWE-613
5.5
2020-11-05 CVE-2020-15950 Insufficient Session Expiration vulnerability in Immuta 2.8.2
Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.
network
low complexity
immuta CWE-613
8.8
2020-10-28 CVE-2020-25374 Insufficient Session Expiration vulnerability in Cyberark Privileged Session Manager 10.9.0.15
CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.
network
high complexity
cyberark CWE-613
2.6
2020-10-28 CVE-2020-24713 Insufficient Session Expiration vulnerability in Getgophish Gophish
Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.
network
low complexity
getgophish CWE-613
7.5