CWE:
 

Topic
Date
Author
Low
MailDepot 2032 SP2 Session Expiration
30.09.2020
Micha Borrmann
Low
Microsoft Office 365 Enterprise E3 Insufficient Session Expiration
09.07.2017
Micha Borrmann


CVEMAP Search Results

CVE
Details
Description
2022-05-03
Medium
CVE-2022-23063

Vendor: Shopizer
Software: Shopizer
 

 
In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.

 
2022-03-25
Low
CVE-2022-25590

Vendor: Surveyking
Software: Surveyking
 

 
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.

 
2022-03-23
Medium
CVE-2022-0996

Vendor: Redhat
Software: 389 director...
 

 
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.

 
2022-03-14
Medium
CVE-2022-24743

Vendor: Sylius
Software: Sylius
 

 
Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password was changed. The same token could be used several times, which could result in leak of the existing token and unauthorized password change. The issue is fixed in versions 1.10.11 and 1.11.2. As a workaround, overwrite the `Sylius\Bundle\ApiBundle\CommandHandler\ResetPasswordHandler` class with code provided by the maintainers and register it in a container. More information about this workaround is available in the GitHub Security Advisory.

 
2022-03-09
Low
CVE-2022-24744

Vendor: Shopware
Software: Shopware
 

 
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged out if the password is reset via password recovery. This issue has been resolved in version 6.4.8.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.

 
Medium
CVE-2022-24732

Vendor: Maddy project
Software: Maddy
 

 
Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating using PAM. Users are advised to upgrade. Users unable to upgrade should manually remove expired accounts via existing filtering mechanisms.

 
2022-03-01
Medium
CVE-2021-38986

Vendor: IBM
Software: MQ
 

 
IBM MQ Appliance 9.2 CD and 9.2 LTS does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 212942.

 
2022-02-25
Medium
CVE-2022-24341

Vendor: Jetbrains
Software: Teamcity
 

 
In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.

 
Medium
CVE-2022-24332

Vendor: Jetbrains
Software: Teamcity
 

 
In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.

 
2022-02-10
Waiting for details
CVE-2021-25992

Updating...
 

 

 

 


Copyright 2022, cxsecurity.com

 

Back to Top