Show filters
48 Total Results
Displaying 11-20 of 48
Sort by:
Attacker Value
Unknown

CVE-2020-10714

Disclosure Date: September 23, 2020 (last updated February 22, 2025)
A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Attacker Value
Unknown

CVE-2020-6302

Disclosure Date: September 09, 2020 (last updated February 22, 2025)
SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequently get access to admin user accounts, leading to Session Fixation and complete compromise of the confidentiality, integrity and availability of the application.
Attacker Value
Unknown

CVE-2020-4243

Disclosure Date: August 04, 2020 (last updated February 21, 2025)
IBM Security Identity Governance and Intelligence 5.2.6 Virtual Appliance could allow a remote attacker to obtain sensitive information using man in the middle techniques due to not properly invalidating session tokens. IBM X-Force ID: 175420.
Attacker Value
Unknown

CVE-2020-4527

Disclosure Date: July 17, 2020 (last updated February 21, 2025)
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the Secure flag for the session cookie in TLS mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. IBM X-Force ID: 182631.
Attacker Value
Unknown

CVE-2020-6290

Disclosure Date: July 14, 2020 (last updated February 21, 2025)
SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID.
Attacker Value
Unknown

CVE-2019-4591

Disclosure Date: July 10, 2020 (last updated February 21, 2025)
IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 167451.
Attacker Value
Unknown

CVE-2020-5596

Disclosure Date: July 07, 2020 (last updated February 21, 2025)
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) does not properly manage sessions, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
Attacker Value
Unknown

CVE-2020-15018

Disclosure Date: June 24, 2020 (last updated February 21, 2025)
playSMS through 1.4.3 is vulnerable to session fixation.
Attacker Value
Unknown

CVE-2020-4229

Disclosure Date: June 04, 2020 (last updated February 21, 2025)
IBM Worklight/MobileFoundation 8.0.0.0 does not properly invalidate session cookies when a user logs out of a session, which could allow another user to gain unauthorized access to a user's session. IBM X-Force ID: 175211.
Attacker Value
Unknown

CVE-2020-13229

Disclosure Date: June 02, 2020 (last updated February 21, 2025)
An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi URI, because it is an authentication token.