VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (453)

page 17 of 23
  • CVE-2022-33927MedAug 10, 2022
    risk 0.35cvss 5.4epss 0.00

    Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by taking advantage of a user with multiple active sessions in order to hijack a user's session.

  • CVE-2021-41268MedNov 24, 2021
    risk 0.35cvss 6.5epss 0.01

    Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version 5.3.0, the cookie is not invalidated when the user changes their password.…

  • CVE-2021-35948MedSep 7, 2021
    risk 0.35cvss 5.4epss 0.01

    Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.

  • CVE-2020-35591MedFeb 18, 2021
    risk 0.35cvss 5.4epss 0.01

    Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in, the injected cookie becomes…

  • CVE-2020-4954MedFeb 15, 2021
    risk 0.35cvss 5.4epss 0.01

    IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to bypass authentication restrictions, caused by improper session validation . By using the configuration panel to obtain a valid session using an attacker controlled IBM Spectrum Protect server, an…

  • CVE-2020-4555MedDec 21, 2020
    risk 0.35cvss 5.4epss 0.01

    IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.

  • CVE-2019-4563MedOct 29, 2020
    risk 0.35cvss 5.3epss 0.01

    IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to…

  • CVE-2019-19610MedMar 16, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0.

  • CVE-2020-5205MedJan 9, 2020
    risk 0.35cvss 6.5epss 0.01

    In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, such as Redis or a database. Cookie store, which is used in most Phoenix apps, doesn't have this…

  • CVE-2010-3671MedNov 5, 2019
    risk 0.35cvss 6.5epss 0.02

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.

  • CVE-2018-13337MedNov 27, 2018
    risk 0.35cvss 5.4epss 0.01

    Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session cookies via JavaScript.

  • CVE-2018-17902MedOct 12, 2018
    risk 0.35cvss 5.3epss 0.01

    Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions.

  • CVE-2018-1000519MedJun 26, 2018
    risk 0.35cvss 6.5epss 0.01

    aio-libs aiohttp-session contains a Session Fixation vulnerability in load_session function for RedisStorage (see: https://github.com/aio-libs/aiohttp-session/blob/master/aiohttp_session/redis_storage.py#L42) that can result in Session Hijacking. This attack appear to be…

  • CVE-2017-2145MedJul 7, 2017
    risk 0.35cvss 5.4epss 0.01

    Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectors.

  • CVE-2016-9851MedDec 11, 2016
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected.

  • CVE-2020-36913MedJan 6, 2026
    risk 0.34cvss 5.3epss 0.00

    All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predefined PHP session identifier during the login process. Attackers can forge HTTP GET requests to welcome.php with a manipulated session token to bypass…

  • CVE-2025-24502MedJan 30, 2025
    risk 0.34cvss —epss 0.00

    An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.

  • CVE-2023-30307MedMay 28, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue discovered in TP-LINK TL-R473GP-AC, TP-LINK XDR6020, TP-LINK TL-R479GP-AC, TP-LINK TL-R4239G, TP-LINK TL-WAR1200L, and TP-LINK TL-R476G routers allows attackers to hijack TCP sessions which could lead to a denial of service.

  • CVE-2024-23193MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.01

    E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node could access other users E-Mails in case they were exported as PDF for a brief moment until caches were cleared.…

  • CVE-2023-34156MedJun 19, 2023
    risk 0.34cvss 5.3epss 0.00

    Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful exploitation of this vulnerability may cause services to be denied.