Vulnerabilities > Insufficient Session Expiration
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-12-18 | CVE-2019-11106 | Insufficient Session Expiration vulnerability in Intel products Insufficient session validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access. | 6.7 |
2019-12-18 | CVE-2019-8803 | Insufficient Session Expiration vulnerability in Apple products An authentication issue was addressed with improved state management. | 8.4 |
2019-11-19 | CVE-2019-12421 | Insufficient Session Expiration vulnerability in Apache Nifi When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token on the client side but not on the server side. | 8.8 |
2019-11-06 | CVE-2019-8149 | Insufficient Session Expiration vulnerability in Magento Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. | 9.8 |
2019-10-16 | CVE-2016-11014 | Insufficient Session Expiration vulnerability in Netgear Jnr1010 Firmware NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case. | 9.8 |
2019-10-09 | CVE-2019-17375 | Insufficient Session Expiration vulnerability in Cpanel cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517). | 8.8 |
2019-09-27 | CVE-2019-9269 | Insufficient Session Expiration vulnerability in Google Android 10.0 In System Settings, there is a possible permissions bypass due to a cached Linux user ID. | 7.3 |
2019-09-22 | CVE-2018-21018 | Insufficient Session Expiration vulnerability in Joinmastodon Mastodon Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions. | 9.8 |
2019-09-18 | CVE-2019-5531 | Insufficient Session Expiration vulnerability in VMWare Esxi, Vcenter Server and Vsphere Esxi VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session expiration. | 5.4 |
2019-09-17 | CVE-2019-14826 | Insufficient Session Expiration vulnerability in multiple products A flaw was found in FreeIPA versions 4.5.0 and later. | 4.4 |