VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (453)

page 13 of 23
  • CVE-2019-10371HigAug 7, 2019
    risk 0.42cvss 7.5epss 0.01

    A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.

  • CVE-2019-7849HigAug 2, 2019
    risk 0.42cvss 7.5epss 0.01

    A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior to 1.9.4.2, Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to…

  • CVE-2019-10045MedMay 31, 2019
    risk 0.42cvss 6.5epss 0.01

    The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the response body, enabling scripts to get access to its value. This identifier can be reused by an attacker to impersonate a user and perform actions on behalf of…

  • CVE-2018-1148MedMay 18, 2018
    risk 0.42cvss 6.5epss 0.01

    In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to session fixation after a user password change.

  • CVE-2017-12225MedSep 7, 2017
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack another user's administrative session, aka a Session Fixation Vulnerability. The vulnerability is due to the reuse of a preauthentication…

  • CVE-2017-5656HigApr 18, 2017
    risk 0.42cvss 7.5epss 0.07

    Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.

  • CVE-2026-86688HigSep 17, 2026
    risk 0.41cvss —epss 0.00

    Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in. AshAuthentication.Plug.Helpers.store_in_session/2 writes the authenticated…

  • CVE-2026-61592HigSep 16, 2026
    risk 0.41cvss 7.4epss 0.00

    djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user — a control the WebSocket transport…

  • CVE-2026-86674MedSep 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is the function session_start of the file login.php. The manipulation results in session fixiation. The attack can be launched…

  • CVE-2026-86279MedSep 7, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the component Login. This manipulation causes session fixiation. It is possible to initiate…

  • CVE-2026-11335MedJun 5, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This impacts the function session_start of the file /login-form.php. Executing a manipulation of the argument UserAuthData can lead…

  • CVE-2025-36115MedJan 20, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.

  • CVE-2025-8517MedAug 4, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in session fixiation. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.0.7 is recommended to address this issue.…

  • CVE-2025-36117MedJul 23, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.

  • CVE-2024-45596HigSep 10, 2024
    risk 0.41cvss 7.4epss 0.01

    Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication URL did not include redirect query string. This happens because on that…

  • CVE-2023-38018MedAug 12, 2024
    risk 0.41cvss 6.3epss 0.00

    IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 260574.

  • CVE-2023-50941MedFeb 2, 2024
    risk 0.41cvss 6.3epss 0.00

    IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using session fixation. IBM X-Force ID: 275131.

  • CVE-2020-6290MedJul 14, 2020
    risk 0.41cvss 6.3epss 0.01

    SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID.

  • CVE-2019-4304MedSep 30, 2019
    risk 0.41cvss 6.3epss 0.01

    IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by improper session validation. IBM X-Force ID: 160950.

  • CVE-2019-12203MedSep 25, 2019
    risk 0.41cvss 6.3epss 0.00

    SilverStripe through 4.3.3 allows session fixation in the "change password" form.