Vulnerabilities > Insufficient Session Expiration

DATE CVE VULNERABILITY TITLE RISK
2023-06-19 CVE-2023-35857 Insufficient Session Expiration vulnerability in Siren Investigate 12.1.7/13.2.0/13.2.1
In Siren Investigate before 13.2.2, session keys remain active even after logging out.
network
low complexity
siren CWE-613
critical
9.8
2023-06-16 CVE-2023-2788 Insufficient Session Expiration vulnerability in Mattermost
Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.
network
low complexity
mattermost CWE-613
6.5
2023-06-05 CVE-2023-0041 Insufficient Session Expiration vulnerability in IBM Security Guardium 11.5
IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration.
network
low complexity
ibm CWE-613
8.8
2023-05-26 CVE-2023-32318 Insufficient Session Expiration vulnerability in Nextcloud Server
Nextcloud server provides a home for data.
local
high complexity
nextcloud CWE-613
6.7
2023-05-22 CVE-2023-31065 Insufficient Session Expiration vulnerability in Apache Inlong 1.4.0/1.5.0/1.6.0
Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.  An old session can be used by an attacker even after the user has been deleted or the password has been changed. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7836 https://github.com/apache/inlong/pull/7836 , https://github.com/apache/inlong/pull/7884 https://github.com/apache/inlong/pull/7884 to solve it.
network
low complexity
apache CWE-613
critical
9.1
2023-05-16 CVE-2023-33005 Insufficient Session Expiration vulnerability in Jenkins Wso2 Oauth
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.
network
low complexity
jenkins CWE-613
5.4
2023-05-09 CVE-2023-31139 Insufficient Session Expiration vulnerability in Dhis2 Dhis 2
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture.
network
low complexity
dhis2 CWE-613
7.5
2023-05-08 CVE-2023-31140 Insufficient Session Expiration vulnerability in Openproject
OpenProject is open source project management software.
network
low complexity
openproject CWE-613
6.5
2023-05-05 CVE-2020-4914 Insufficient Session Expiration vulnerability in IBM Cloud PAK System
IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local user to impersonate another user on the system.
local
low complexity
ibm CWE-613
5.5
2023-05-05 CVE-2022-38707 Insufficient Session Expiration vulnerability in IBM Cognos Command Center 10.2.4.1
IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration.
local
low complexity
ibm CWE-613
5.5