Skip to main content

CWE archive

CWE-384 CVEs

Programmatic archive

414 CVEs tagged with CWE-38472 Critical, 150 High, 164 Medium, 27 Low, 1 Unrated.

CVE-2018-1000409

Published Jan 9, 2019

A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1804

Published Dec 13, 2018

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not set the secure attribute on authorization tokens or session cookies. This could allo…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-1485

Published Dec 12, 2018

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking v…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-1484

Published Dec 12, 2018

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cooki…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-1480

Published Dec 12, 2018

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly' attribute on authorization tokens or session cookies. If a Cross-Site Scripting vulnerab…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19443

Published Nov 22, 2018

The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in bus.py and jsonrpc.py. This connection…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6434

Published Nov 8, 2018

A vulnerability in the web management interface of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow attackers to intercept or manipulate a user's sessio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18926

Published Nov 4, 2018

Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-macaron/session code for Macaro…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-18925

Published Nov 4, 2018

Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-13282

Published Oct 31, 2018

Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16463

Published Oct 30, 2018

A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-18380

Published Oct 19, 2018

A Session Fixation issue was discovered in Bigtree before 4.2.24. admin.php accepts a user-provided PHP session ID instead of regenerating a new one after a user has logged in to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8852

Published Sep 26, 2018

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, the software gives an attacker the oppo…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-1127

Published Sep 11, 2018

Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for a few minutes allowing attack…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8609

Published Aug 1, 2018

It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijac…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-5385

Published Jul 24, 2018

Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to bypassing the two factor authentication in some inst…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14387

Published Jul 18, 2018

An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6545

Published Jul 13, 2018

Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base64 encoded passwd field on eve…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1492

Published Jul 10, 2018

IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous sess…

CVSS 4.3 · Medium

CVE-2018-1000602

Published Jun 26, 2018

A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 414 CVEsPage 14 of 17