Vulnerabilities > Session Fixation

DATE CVE VULNERABILITY TITLE RISK
2018-05-30 CVE-2018-11567 Session Fixation vulnerability in Amazon products
Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill.
local
low complexity
amazon CWE-384
3.3
2018-05-29 CVE-2018-1375 Session Fixation vulnerability in IBM Security Guardium BIG Data Intelligence 3.1
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability.
network
low complexity
ibm CWE-384
7.5
2018-05-25 CVE-2018-11475 Session Fixation vulnerability in Monstra 3.0.4
Monstra CMS 3.0.4 has a Session Management Issue in the Users tab.
network
low complexity
monstra CWE-384
8.0
2018-05-25 CVE-2018-11474 Session Fixation vulnerability in Monstra 3.0.4
Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab.
network
low complexity
monstra CWE-384
8.0
2018-05-18 CVE-2018-1148 Session Fixation vulnerability in Tenable Nessus
In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application.
network
low complexity
tenable CWE-384
6.5
2018-05-15 CVE-2018-10591 Session Fixation vulnerability in Advantech products
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an origin validation error vulnerability has been identified, which may allow an attacker can create a malicious web site, steal session cookies, and access data of authenticated users.
network
high complexity
advantech CWE-384
6.1
2018-05-14 CVE-2018-10252 Session Fixation vulnerability in Actiontec Wcb6200Q Firmware
An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices.
network
high complexity
actiontec CWE-384
8.1
2018-05-08 CVE-2018-1000173 Session Fixation vulnerability in Jenkins Google Login
A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.
network
high complexity
jenkins CWE-384
5.9
2018-05-01 CVE-2013-2049 Session Fixation vulnerability in Redhat Cloudforms Management Engine 2.0
Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret.
network
low complexity
redhat CWE-384
7.5
2018-04-20 CVE-2018-0564 Session Fixation vulnerability in Lockon Ec-Cube
Session fixation vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3..4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-CUBE 3.0.7, EC-CUBE 3.0.8, EC-CUBE 3.0.9, EC-CUBE 3.0.10, EC-CUBE 3.0.11, EC-CUBE 3.0.12, EC-CUBE 3.0.12-p1, EC-CUBE 3.0.13, EC-CUBE 3.0.14, EC-CUBE 3.0.15) allows remote attackers to perform arbitrary operations via unspecified vectors.
network
low complexity
lockon CWE-384
8.1