CVE-2016-6040

CVSS v3 Score
5.0
Medium
CVSS v2 Score
6.0
Medium

Vulnerability Description

IBM Jazz Foundation could allow an authenticated user to take over a previously logged in user due to session expiration not being enforced.

CVSS:5.0(Medium)

IBM Storage Scale 5.1.0.0 through 5.1.9.2 could allow an authenticated user to steal or manipulate an active session to gain access to the system. IBM X-Force ID: 260208.

CVSS:5.1(Medium)

IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a close...

CVSS:4.9(Medium)

Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions befor...

CVSS:4.8(Medium)

Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixation.

CVSS:4.8(Medium)

This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

CVSS:5.3(Medium)

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly' attribute on authorization tokens or session cookies. If a Cross-Site Scripting vulnerability also existed at...