VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (435)

page 19 of 22
  • CVE-2023-3192MedJun 11, 2023
    risk 0.28cvss 5.4epss 0.00

    Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.

  • CVE-2022-43687MedNov 14, 2022
    risk 0.28cvss 5.4epss 0.01

    Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 does not issue a new session ID upon successful OAuth authentication. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.

  • CVE-2022-1849MedMay 24, 2022
    risk 0.28cvss 5.4epss 0.01

    Session Fixation in GitHub repository filegator/filegator prior to 7.8.0.

  • CVE-2020-4291MedApr 8, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could disclose sensitive information to an unauthorized user due to insufficient timeout functionality in the Web UI. IBM X-Force ID: 176334.

  • CVE-2018-1948MedFeb 21, 2019
    risk 0.28cvss 4.3epss 0.01

    IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a…

  • CVE-2018-1000409MedJan 9, 2019
    risk 0.28cvss 5.4epss 0.01

    A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented Jenkins from invalidating the existing session and creating a new one when a user signed up for a…

  • CVE-2017-1368MedAug 6, 2018
    risk 0.28cvss 4.3epss 0.01

    IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user…

  • CVE-2018-1492MedJul 10, 2018
    risk 0.28cvss 4.3epss 0.00

    IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977.

  • CVE-2017-1152MedApr 14, 2017
    risk 0.28cvss 4.3epss 0.01

    IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.

  • CVE-2025-4644MedAug 29, 2025
    risk 0.27cvss epss 0.00

    A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT), and then delete the account, which did not invalidate the JWT. As a result, the…

  • CVE-2024-48929MedOct 22, 2024
    risk 0.27cvss 4.2epss 0.00

    Umbraco is a free and open source .NET content management system. In versions on the 13.x branch prior to 13.5.2 and versions on the 10.x branch prior to 10.8.7, during an explicit sign-out, the server session is not fully terminated. Versions 13.5.2 and 10.8.7 contain a patch…

  • CVE-2022-4231MedNov 30, 2022
    risk 0.27cvss 4.2epss 0.00

    A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to session fixiation. The attack may be initiated remotely. The…

  • CVE-2018-1962MedFeb 4, 2019
    risk 0.26cvss 4.0epss 0.00

    IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is pressed. The lack of proper session termination may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 153658.

  • CVE-2018-1480MedDec 12, 2018
    risk 0.26cvss 4.0epss 0.01

    IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly' attribute on authorization tokens or session cookies. If a Cross-Site Scripting vulnerability also existed attackers may be able to get the cookie values via malicious JavaScript and then…

  • CVE-2023-45718LowFeb 9, 2024
    risk 0.25cvss 3.9epss 0.00

    Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.  

  • CVE-2026-59883MedJul 8, 2026
    risk 0.24cvss 4.7epss 0.00

    Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1,…

  • CVE-2022-25896MedJul 1, 2022
    risk 0.24cvss 4.8epss 0.01

    This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

  • CVE-2020-4243LowAug 5, 2020
    risk 0.24cvss 3.7epss 0.01

    IBM Security Identity Governance and Intelligence 5.2.6 Virtual Appliance could allow a remote attacker to obtain sensitive information using man in the middle techniques due to not properly invalidating session tokens. IBM X-Force ID: 175420.

  • CVE-2020-1993LowMay 13, 2020
    risk 0.24cvss 3.7epss 0.00

    The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks, if an attacker is able to control a user's session ID. This issue affects: All PAN-OS 7.1 and 8.0 versions; PAN-OS 8.1 versions…

  • CVE-2018-1804LowDec 13, 2018
    risk 0.24cvss 3.7epss 0.01

    IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID:…