VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (435)

page 5 of 22
  • CVE-2023-24424HigJan 26, 2023
    risk 0.57cvss 8.8epss 0.01

    Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login.

  • CVE-2021-29368HigJan 20, 2023
    risk 0.57cvss 8.8epss 0.01

    Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 allows attackers to gain access to arbitrary user sessions.

  • CVE-2022-44007HigNov 16, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is possible for an attacker to trick users into opening an authenticated user session for a session identifier known to the attacker, aka Session Fixation.

  • CVE-2022-3269CriSep 23, 2022
    risk 0.57cvss 9.8epss 0.01

    Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.

  • CVE-2022-38369HigSep 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

  • CVE-2022-27305HigMay 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.

  • CVE-2021-39066HigFeb 2, 2022
    risk 0.57cvss 8.8epss 0.01

    IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.

  • CVE-2018-16495HigMay 26, 2021
    risk 0.57cvss 8.8epss 0.01

    In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed after the user successfully logs into the application. Failing to issue a new session ID following a successful login introduces the possibility for an…

  • CVE-2020-35229HigMar 10, 2021
    risk 0.57cvss 8.8epss 0.01

    The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which allows attackers (with access to network traffic) to effectively gain…

  • CVE-2020-25198HigDec 23, 2020
    risk 0.57cvss 8.8epss 0.01

    The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protections from session fixation, which may allow an attacker to gain access to a session and hijack it by stealing the user’s cookies.

  • CVE-2020-15909HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.02

    SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Central JSESSIONID cookie attribute is not checked against multiple sources such as sourceip, MFA claim, etc. as long as the victim stays logged in within…

  • CVE-2020-13229HigJun 2, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi URI, because it is an authentication token.

  • CVE-2019-10158CriJan 2, 2020
    risk 0.57cvss 9.8epss 0.02

    A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.

  • CVE-2019-18573HigDec 18, 2019
    risk 0.57cvss 8.8epss 0.01

    The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the…

  • CVE-2019-17062HigNov 5, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Version: 4.9.x-4.10.x. By using a specially crafted URL, users…

  • CVE-2019-13517HigSep 6, 2019
    risk 0.57cvss 8.8epss 0.01

    In Pyxis ES Versions 1.3.4 through to 1.6.1 and Pyxis Enterprise Server, with Windows Server Versions 4.4 through 4.12, a vulnerability has been identified where existing access privileges are not restricted in coordination with the expiration of access based on active directory…

  • CVE-2019-10120HigJul 10, 2019
    risk 0.57cvss 8.8epss 0.01

    On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAutoLogin) can be achieved by continuing to use a session ID after a logout, aka HMCCU-154.

  • CVE-2019-6584HigJun 12, 2019
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx), SIEMENS LOGO!8 (6ED1052-xyy08-0BA0 FS:01 / Firmware version < V1.82.02). The integrated webserver does not invalidate the Session ID upon user…

  • CVE-2015-5384HigApr 3, 2019
    risk 0.57cvss 8.8epss 0.01

    AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier is vulnerable to a Session Fixation attack.

  • CVE-2019-9744HigMar 26, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered on PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M, and FL NAT SMN 8TX-M-DMG devices. There is unauthorized access to the WEB-UI by attackers arriving from the same source IP address as an authenticated user, because this IP address is…