Vulnerabilities > Session Fixation

DATE CVE VULNERABILITY TITLE RISK
2020-01-02 CVE-2019-10158 Session Fixation vulnerability in multiple products
A flaw was found in Infinispan through version 9.4.14.Final.
network
low complexity
infinispan redhat CWE-384
critical
9.8
2019-12-23 CVE-2019-17563 Session Fixation vulnerability in multiple products
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack.
network
high complexity
apache debian opensuse canonical oracle CWE-384
7.5
2019-12-18 CVE-2019-18573 Session Fixation vulnerability in Dell RSA Identity Governance and Lifecycle
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability.
network
low complexity
dell CWE-384
8.8
2019-11-05 CVE-2019-8116 Session Fixation vulnerability in Magento
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
network
low complexity
magento CWE-384
7.5
2019-11-05 CVE-2010-3671 Session Fixation vulnerability in Typo3
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.
network
low complexity
typo3 CWE-384
6.5
2019-11-05 CVE-2019-17062 Session Fixation vulnerability in Oxid-Esales Eshop
An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Version: 4.9.x-4.10.x.
network
low complexity
oxid-esales CWE-384
8.8
2019-10-24 CVE-2019-18418 Session Fixation vulnerability in Clonos 19.09
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.
network
low complexity
clonos CWE-384
critical
9.8
2019-10-17 CVE-2019-15849 Session Fixation vulnerability in Eq-3 Homematic Ccu3 Firmware 3.14.11
eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation.
network
low complexity
eq-3 CWE-384
7.3
2019-10-09 CVE-2019-0062 Session Fixation vulnerability in Juniper Junos
A session fixation vulnerability in J-Web on Junos OS may allow an attacker to use social engineering techniques to fix and hijack a J-Web administrators web session and potentially gain administrative access to the device.
network
low complexity
juniper CWE-384
8.8
2019-10-04 CVE-2019-4227 Session Fixation vulnerability in IBM MQ
IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unauthorized user to conduct a session fixation attack due to clients not being disconnected as they should.
network
low complexity
ibm CWE-384
7.3