Skip to main content

CWE archive

CWE-384 CVEs

Programmatic archive

414 CVEs tagged with CWE-38472 Critical, 150 High, 164 Medium, 27 Low, 1 Unrated.

CVE-2018-1000519

Published Jun 26, 2018

aio-libs aiohttp-session contains a Session Fixation vulnerability in load_session function for RedisStorage (see: https://github.com/aio-libs/aiohttp-session/blob/master/aiohttp_…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0359

Published Jun 21, 2018

A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an unauthenticated, local attacke…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9026

Published Jun 18, 2018

A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions with a specially crafted request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12071

Published Jun 17, 2018

A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1375

Published May 29, 2018

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnera…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11475

Published May 25, 2018

Monstra CMS 3.0.4 has a Session Management Issue in the Users tab. A password change at users/1/edit does not invalidate a session that is open in a different browser.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11474

Published May 25, 2018

Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab. A password change at admin/index.php?id=users&action=edit&user_id=1 does not invalidate a session that…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1148

Published May 18, 2018

In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to sessio…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000173

Published May 8, 2018

A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another u…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2049

Published May 1, 2018

Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0564

Published Apr 20, 2018

Session fixation vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3..4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-CUBE 3.0.7, EC-CUBE 3.0.8, EC…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6959

Published Apr 13, 2018

VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of this issue may lead to the hijacking of a valid vRA user's…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-2409

Published Apr 10, 2018

Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some other user may be shown or modifie…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-2408

Published Apr 10, 2018

Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other act…

CVSS 7.3 · High
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort
Showing 351-375 of 414 CVEsPage 15 of 17