Vulnerabilities > Session Fixation

DATE CVE VULNERABILITY TITLE RISK
2018-05-15 CVE-2018-10591 Session Fixation vulnerability in Advantech products
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an origin validation error vulnerability has been identified, which may allow an attacker can create a malicious web site, steal session cookies, and access data of authenticated users.
network
high complexity
advantech CWE-384
6.1
2018-05-14 CVE-2018-10252 Session Fixation vulnerability in Actiontec Wcb6200Q Firmware
An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices.
network
high complexity
actiontec CWE-384
8.1
2018-05-08 CVE-2018-1000173 Session Fixation vulnerability in Jenkins Google Login
A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.
network
high complexity
jenkins CWE-384
5.9
2018-05-01 CVE-2013-2049 Session Fixation vulnerability in Redhat Cloudforms Management Engine 2.0
Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret.
network
low complexity
redhat CWE-384
7.5
2018-04-20 CVE-2018-0564 Session Fixation vulnerability in Lockon Ec-Cube
Session fixation vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3..4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-CUBE 3.0.7, EC-CUBE 3.0.8, EC-CUBE 3.0.9, EC-CUBE 3.0.10, EC-CUBE 3.0.11, EC-CUBE 3.0.12, EC-CUBE 3.0.12-p1, EC-CUBE 3.0.13, EC-CUBE 3.0.14, EC-CUBE 3.0.15) allows remote attackers to perform arbitrary operations via unspecified vectors.
network
low complexity
lockon CWE-384
8.1
2018-04-19 CVE-2018-0229 Session Fixation vulnerability in Cisco products
A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (SSO) authentication for Cisco AnyConnect Secure Mobility Client for Desktop Platforms, Cisco Adaptive Security Appliance (ASA) Software, and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish an authenticated AnyConnect session through an affected device running ASA or FTD Software.
network
low complexity
cisco CWE-384
6.5
2018-04-13 CVE-2018-6959 Session Fixation vulnerability in VMWare Vrealize Automation
VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs.
network
low complexity
vmware CWE-384
critical
9.8
2018-04-11 CVE-2017-18125 Session Fixation vulnerability in Qualcomm products
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835, SD 845, SD 850, when secure camera is activated it stores captured data in protected buffers.
network
low complexity
qualcomm CWE-384
7.5
2018-04-10 CVE-2018-2409 Session Fixation vulnerability in SAP Cloud Platform 2.0
Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector).
network
low complexity
sap CWE-384
8.8
2018-04-10 CVE-2018-2408 Session Fixation vulnerability in SAP Businessobjects
Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad.
network
low complexity
sap CWE-384
7.3