VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (435)

page 17 of 22
  • CVE-2016-9851MedDec 11, 2016
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected.

  • CVE-2020-36913MedJan 6, 2026
    risk 0.34cvss 5.3epss 0.00

    All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predefined PHP session identifier during the login process. Attackers can forge HTTP GET requests to welcome.php with a manipulated session token to bypass…

  • CVE-2025-24502MedJan 30, 2025
    risk 0.34cvss epss 0.00

    An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.

  • CVE-2023-30307MedMay 28, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue discovered in TP-LINK TL-R473GP-AC, TP-LINK XDR6020, TP-LINK TL-R479GP-AC, TP-LINK TL-R4239G, TP-LINK TL-WAR1200L, and TP-LINK TL-R476G routers allows attackers to hijack TCP sessions which could lead to a denial of service.

  • CVE-2024-23193MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.01

    E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node could access other users E-Mails in case they were exported as PDF for a brief moment until caches were cleared.…

  • CVE-2023-34156MedJun 19, 2023
    risk 0.34cvss 5.3epss 0.00

    Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful exploitation of this vulnerability may cause services to be denied.

  • CVE-2022-24895MedFeb 3, 2023
    risk 0.34cvss 6.3epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the rest of session attributes. Because this does not clear CSRF tokens upon login,…

  • CVE-2014-125048MedJan 6, 2023
    risk 0.34cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in kassi xingwall. This issue affects some unknown processing of the file app/controllers/oauth.js. The manipulation leads to session fixiation. The patch is named e9f0d509e1408743048e29d9c099d36e0e1f6ae7. It is…

  • CVE-2019-4439MedJul 25, 2019
    risk 0.34cvss 5.3epss 0.00

    IBM Cloud Private 3.1.0, 3.1.1, and 3.1.2 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 162949.

  • CVE-2025-64100MedOct 29, 2025
    risk 0.33cvss 6.1epss 0.00

    CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.9 and 2.11.4, session ids could be fixed by an attacker if the site is configured with server-side session storage (CKAN uses cookie-based session storage by default). The…

  • CVE-2023-38002MedApr 30, 2024
    risk 0.33cvss 5.0epss 0.00

    IBM Storage Scale 5.1.0.0 through 5.1.9.2 could allow an authenticated user to steal or manipulate an active session to gain access to the system. IBM X-Force ID: 260208.

  • CVE-2016-6040MedFeb 1, 2017
    risk 0.33cvss 5.0epss 0.01

    IBM Jazz Foundation could allow an authenticated user to take over a previously logged in user due to session expiration not being enforced.

  • CVE-2025-12390MedOct 28, 2025
    risk 0.32cvss 6.0epss 0.00

    A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak sometimes reuses session identifiers and doesn’t clean up properly during logout when browser…

  • CVE-2026-33384MedMay 29, 2026
    risk 0.31cvss epss 0.00

    QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in…

  • CVE-2026-33946MedMar 27, 2026
    risk 0.31cvss 5.9epss 0.00

    MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby SDK's streamable_http_transport.rb implementation contains a session hijacking vulnerability. An attacker who obtains a valid session ID can completely hijack…

  • CVE-2025-70973MedMar 9, 2026
    risk 0.31cvss 4.8epss 0.00

    ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after successful authentication. As a result, a session created prior to login becomes authenticated once…

  • CVE-2024-30262MedApr 9, 2024
    risk 0.31cvss 5.9epss 0.01

    Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to…

  • CVE-2022-24745MedMar 9, 2022
    risk 0.31cvss 4.8epss 0.01

    Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inconsistent experiences for guest users. Setups with Varnish…

  • CVE-2021-32710MedJun 24, 2021
    risk 0.31cvss 5.9epss 0.01

    Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2. We recommend to update to the current version 6.3.5.2. You can get the update to 6.3.5.2 regularly via the Auto-Updater or directly via the download overview.…

  • CVE-2019-18946MedFeb 26, 2021
    risk 0.31cvss 4.8epss 0.00

    Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixation.