Vulnerabilities > Session Fixation

DATE CVE VULNERABILITY TITLE RISK
2018-10-12 CVE-2018-17902 Session Fixation vulnerability in Yokogawa products
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions.
network
low complexity
yokogawa CWE-384
5.3
2018-09-28 CVE-2018-9082 Session Fixation vulnerability in Lenovo products
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one.
network
low complexity
lenovo CWE-384
8.8
2018-09-26 CVE-2018-8852 Session Fixation vulnerability in Philips E-Alert Firmware 2.1/R2.1
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
network
low complexity
philips CWE-384
8.8
2018-09-11 CVE-2018-1127 Session Fixation vulnerability in Redhat Gluster Storage
Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out.
network
high complexity
redhat CWE-384
8.1
2018-08-06 CVE-2017-1368 Session Fixation vulnerability in IBM Security Identity Governance and Intelligence
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorization tokens or session cookies.
network
low complexity
ibm CWE-384
6.5
2018-07-24 CVE-2018-5385 Session Fixation vulnerability in Navarino Infinity 2.2
Navarino Infinity is prone to session fixation attacks.
network
low complexity
navarino CWE-384
8.8
2018-07-19 CVE-2016-9574 Session Fixation vulnerability in Mozilla Network Security Services
nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicket extension and ECDHE-ECDSA.
network
high complexity
mozilla CWE-384
5.9
2018-07-18 CVE-2018-14387 Session Fixation vulnerability in Wondercms
An issue was discovered in WonderCMS before 2.5.2.
network
low complexity
wondercms CWE-384
8.8
2018-07-13 CVE-2016-6545 Session Fixation vulnerability in Ieasytec Itrackeasy
Session cookies are not used for maintaining valid sessions in iTrack Easy.
network
low complexity
ieasytec CWE-384
critical
9.8
2018-07-10 CVE-2018-1492 Session Fixation vulnerability in IBM products
IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session.
low complexity
ibm CWE-384
6.8