Vulnerabilities > Session Fixation

DATE CVE VULNERABILITY TITLE RISK
2019-07-10 CVE-2019-10120 Session Fixation vulnerability in Eq-3 Ccu2 Firmware and Ccu3 Firmware
On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAutoLogin) can be achieved by continuing to use a session ID after a logout, aka HMCCU-154.
network
low complexity
eq-3 CWE-384
8.8
2019-06-25 CVE-2019-4152 Session Fixation vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner.
local
low complexity
ibm CWE-384
4.4
2019-05-31 CVE-2019-10045 Session Fixation vulnerability in Pydio
The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the response body, enabling scripts to get access to its value.
network
low complexity
pydio CWE-384
6.5
2019-05-03 CVE-2019-1807 Session Fixation vulnerability in Cisco Umbrella
A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user session.
network
low complexity
cisco CWE-384
8.8
2019-04-30 CVE-2018-15208 Session Fixation vulnerability in Bpcbt Smartvista 2
BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.
network
high complexity
bpcbt CWE-384
7.5
2019-04-24 CVE-2019-10008 Session Fixation vulnerability in Zohocorp Servicedesk Plus 9.3
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.
network
low complexity
zohocorp CWE-384
8.8
2019-04-23 CVE-2017-12619 Session Fixation vulnerability in Apache Zeppelin
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session.
network
low complexity
apache CWE-384
8.1
2019-04-12 CVE-2019-11213 Session Fixation vulnerability in multiple products
In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end user, a related issue to CVE-2019-1573.
network
high complexity
pulsesecure ivanti CWE-384
8.1
2019-04-03 CVE-2015-5384 Session Fixation vulnerability in Axiomsl Axiom 9.5.3
AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier is vulnerable to a Session Fixation attack.
network
low complexity
axiomsl CWE-384
8.8
2019-04-02 CVE-2018-1626 Session Fixation vulnerability in IBM Security Privileged Identity Manager 2.1.1
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability.
network
low complexity
ibm CWE-384
4.3