Vulnerabilities > Session Fixation

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-18573 Session Fixation vulnerability in Dell RSA Identity Governance and Lifecycle
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability.
network
low complexity
dell CWE-384
8.8
2019-11-05 CVE-2019-8116 Session Fixation vulnerability in Magento
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
network
low complexity
magento CWE-384
7.5
2019-11-05 CVE-2010-3671 Session Fixation vulnerability in Typo3
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.
network
low complexity
typo3 CWE-384
6.5
2019-11-05 CVE-2019-17062 Session Fixation vulnerability in Oxid-Esales Eshop
An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Version: 4.9.x-4.10.x.
network
low complexity
oxid-esales CWE-384
8.8
2019-10-24 CVE-2019-18418 Session Fixation vulnerability in Clonos 19.09
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.
network
low complexity
clonos CWE-384
critical
9.8
2019-10-17 CVE-2019-15849 Session Fixation vulnerability in Eq-3 Homematic Ccu3 Firmware 3.14.11
eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation.
network
low complexity
eq-3 CWE-384
7.3
2019-10-09 CVE-2019-0062 Session Fixation vulnerability in Juniper Junos
A session fixation vulnerability in J-Web on Junos OS may allow an attacker to use social engineering techniques to fix and hijack a J-Web administrators web session and potentially gain administrative access to the device.
network
low complexity
juniper CWE-384
8.8
2019-10-04 CVE-2019-4227 Session Fixation vulnerability in IBM MQ
IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unauthorized user to conduct a session fixation attack due to clients not being disconnected as they should.
network
low complexity
ibm CWE-384
7.3
2019-09-30 CVE-2019-4304 Session Fixation vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by improper session validation.
network
low complexity
ibm CWE-384
6.3
2019-09-26 CVE-2019-6161 Session Fixation vulnerability in Lenovo CP Storage Block Firmware
An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmware versions prior to 1908.M.
network
low complexity
lenovo CWE-384
7.5