VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (435)

page 2 of 22
  • CVE-2024-8643CriSep 27, 2024
    risk 0.64cvss 9.8epss 0.00

    Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking. This issue affects ValeApp: before v2.0.0.

  • CVE-2023-48929CriDec 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the group_status.asp resource allows an attacker to escalate privileges and obtain sensitive information.

  • CVE-2023-42322CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information.

  • CVE-2023-41012CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism.

  • CVE-2023-31498CriMay 11, 2023
    risk 0.64cvss 9.8epss 0.02

    A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter.

  • CVE-2023-28316CriMay 9, 2023
    risk 0.64cvss 9.8epss 0.01

    A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This could potentially allow an attacker to maintain access to a compromised account even after 2FA is…

  • CVE-2021-36394CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.07

    In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

  • CVE-2023-24444CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login.

  • CVE-2022-31689CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.

  • CVE-2022-40293CriOct 31, 2022
    risk 0.64cvss 9.8epss 0.01

    The application was vulnerable to a session fixation that could be used hijack accounts.

  • CVE-2022-38054CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.02

    In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.

  • CVE-2021-38869CriApr 27, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.

  • CVE-2021-41553CriOct 5, 2021
    risk 0.64cvss 9.8epss 0.01

    In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session token that could be already in use by another user. It was therefore possible to access the application through a user whose credentials were not known, without…

  • CVE-2021-39290CriAug 23, 2021
    risk 0.64cvss 9.8epss 0.02

    Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.

  • CVE-2020-8434CriMay 19, 2020
    risk 0.64cvss 9.8epss 0.01

    Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch 8 has session cookies that are a deterministic function of the username. There is a hard-coded password to supply a PBKDF feeding into AES to encrypt a…

  • CVE-2020-11729CriApr 15, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.

  • CVE-2020-5543CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.02

    TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not properly manage sessions, which allows remote attackers to stop the network functions or execute malware via a specially crafted packet.

  • CVE-2019-5523CriApr 1, 2019
    risk 0.64cvss 9.8epss 0.03

    VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and Provider Portals. Successful exploitation of this issue may allow a malicious actor to access the Tenant or Provider Portals by…

  • CVE-2016-6545CriJul 13, 2018
    risk 0.64cvss 9.8epss 0.03

    Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base64 encoded passwd field on every request. In this implementation, sessions can only be terminated when the user changes the…

  • CVE-2018-6959CriApr 13, 2018
    risk 0.64cvss 9.8epss 0.02

    VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of this issue may lead to the hijacking of a valid vRA user's session.