VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (435)

page 13 of 22
  • CVE-2025-8517MedAug 4, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in session fixiation. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.0.7 is recommended to address this issue.…

  • CVE-2025-36117MedJul 23, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.

  • CVE-2024-45596HigSep 10, 2024
    risk 0.41cvss 7.4epss 0.01

    Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication URL did not include redirect query string. This happens because on that…

  • CVE-2023-38018MedAug 12, 2024
    risk 0.41cvss 6.3epss 0.00

    IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 260574.

  • CVE-2023-50941MedFeb 2, 2024
    risk 0.41cvss 6.3epss 0.00

    IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using session fixation. IBM X-Force ID: 275131.

  • CVE-2020-6290MedJul 14, 2020
    risk 0.41cvss 6.3epss 0.01

    SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID.

  • CVE-2019-4304MedSep 30, 2019
    risk 0.41cvss 6.3epss 0.01

    IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by improper session validation. IBM X-Force ID: 160950.

  • CVE-2019-12203MedSep 25, 2019
    risk 0.41cvss 6.3epss 0.00

    SilverStripe through 4.3.3 allows session fixation in the "change password" form.

  • CVE-2019-5400MedAug 9, 2019
    risk 0.41cvss 6.3epss 0.01

    A remote session reuse vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

  • CVE-2018-2409MedApr 10, 2018
    risk 0.41cvss 6.3epss 0.01

    Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some other user may be shown or modified when using an application built on top of SAP Cloud Platform.

  • CVE-2025-46605MedApr 17, 2026
    risk 0.40cvss 6.2epss 0.00

    Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized…

  • CVE-2026-33492HigMar 23, 2026
    risk 0.40cvss 7.3epss 0.00

    WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function accepts arbitrary session IDs via the `PHPSESSID` GET parameter and sets them as the active PHP session. A session regeneration bypass exists for specific…

  • CVE-2025-63529MedDec 1, 2025
    risk 0.40cvss 6.1epss 0.00

    A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier prior to authentication. When the victim logs in, the application continues to use the attacker-supplied session ID…

  • CVE-2024-25977HigMay 29, 2024
    risk 0.40cvss 7.3epss 0.01

    The application does not change the session token when using the login or logout functionality. An attacker can set a session token in the victim's browser (e.g. via XSS) and prompt the victim to log in (e.g. via a redirect to the login page). This results in the victim's…

  • CVE-2022-38628MedDec 13, 2022
    risk 0.40cvss 6.1epss 0.01

    Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a cross-site scripting (XSS) vulnerability which is chained with a local session fixation. This vulnerability allows attackers to escalate…

  • CVE-2022-31798MedAug 25, 2022
    risk 0.40cvss 6.1epss 0.07

    Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.

  • CVE-2021-35046MedJun 22, 2021
    risk 0.40cvss 6.1epss 0.01

    A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user session via a crafted session cookie.

  • CVE-2014-10400MedFeb 6, 2020
    risk 0.40cvss 6.1epss 0.01

    The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.

  • CVE-2014-10399MedFeb 6, 2020
    risk 0.40cvss 6.1epss 0.01

    The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.

  • CVE-2018-10591MedMay 15, 2018
    risk 0.40cvss 6.1epss 0.01

    In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an origin validation error vulnerability has been…