Vulnerabilities > Session Fixation

DATE CVE VULNERABILITY TITLE RISK
2020-06-02 CVE-2020-13229 Session Fixation vulnerability in Sysax Multi Server 6.90
An issue was discovered in Sysax Multi Server 6.90.
network
low complexity
sysax CWE-384
8.8
2020-05-19 CVE-2020-8434 Session Fixation vulnerability in Jenzabar Internet Campus Solution
Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch 8 has session cookies that are a deterministic function of the username.
network
low complexity
jenzabar CWE-384
critical
9.8
2020-05-18 CVE-2020-12258 Session Fixation vulnerability in Rconfig 3.9.4
rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled.
network
low complexity
rconfig CWE-384
critical
9.1
2020-05-13 CVE-2020-1993 Session Fixation vulnerability in Paloaltonetworks Pan-Os
The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks, if an attacker is able to control a user's session ID.
network
low complexity
paloaltonetworks CWE-384
5.4
2020-05-07 CVE-2020-5894 Session Fixation vulnerability in F5 Nginx Controller
On versions 3.0.0-3.3.0, the NGINX Controller webserver does not invalidate the server-side session token after users log out.
network
low complexity
f5 CWE-384
8.1
2020-04-29 CVE-2020-12467 Session Fixation vulnerability in Intelliants Subrion 4.2.1
Subrion CMS 4.2.1 allows session fixation via an alphanumeric value in a session cookie.
network
low complexity
intelliants CWE-384
6.5
2020-04-27 CVE-2020-1762 Session Fixation vulnerability in multiple products
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.
network
low complexity
kiali redhat CWE-384
8.6
2020-04-24 CVE-2020-6824 Session Fixation vulnerability in Mozilla Firefox
Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open.
local
low complexity
mozilla CWE-384
2.8
2020-04-15 CVE-2020-11729 Session Fixation vulnerability in multiple products
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60.
network
low complexity
davical debian CWE-384
critical
9.8
2020-04-15 CVE-2020-11728 Session Fixation vulnerability in multiple products
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60.
network
low complexity
davical debian CWE-384
7.5