VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (435)

page 8 of 22
  • CVE-2018-10252HigMay 14, 2018
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices. The admin login session cookie is insecurely generated making admin session hijacking possible. When an admin logs in, a session cookie is generated using the time of day rounded to 10ms. Since the web…

  • CVE-2018-0564HigApr 20, 2018
    risk 0.53cvss 8.1epss 0.02

    Session fixation vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3..4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-CUBE 3.0.7, EC-CUBE 3.0.8, EC-CUBE 3.0.9, EC-CUBE 3.0.10, EC-CUBE 3.0.11, EC-CUBE 3.0.12, EC-CUBE 3.0.12-p1, EC-CUBE 3.0.13,…

  • CVE-2017-14263HigSep 11, 2017
    risk 0.53cvss 8.1epss 0.04

    Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with…

  • CVE-2016-9981HigAug 2, 2017
    risk 0.53cvss 8.1epss 0.01

    IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an attacker to hijack a valid user's session. IBM X-Force ID: 120257

  • CVE-2017-4963HigJun 13, 2017
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v2.0.0 - v2.7.4.12 & v3.0.0 - v3.11.0, and UAA bosh release v26 & earlier versions. UAA is vulnerable to session fixation when configured to authenticate…

  • CVE-2009-10007CriJun 9, 2026
    risk 0.52cvss 9.1epss 0.00

    Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to…

  • CVE-2025-54761HigSep 19, 2025
    risk 0.52cvss 8.0epss 0.00

    An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.

  • CVE-2023-22648HigJun 1, 2023
    risk 0.52cvss 8.0epss 0.00

    A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in Rancher, even if they change groups on…

  • CVE-2018-11475HigMay 25, 2018
    risk 0.52cvss 8.0epss 0.01

    Monstra CMS 3.0.4 has a Session Management Issue in the Users tab. A password change at users/1/edit does not invalidate a session that is open in a different browser.

  • CVE-2018-11474HigMay 25, 2018
    risk 0.52cvss 8.0epss 0.01

    Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab. A password change at admin/index.php?id=users&action=edit&user_id=1 does not invalidate a session that is open in a different browser.

  • CVE-2016-8638CriJul 12, 2017
    risk 0.52cvss 9.1epss 0.02

    A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an unauthenticated attacker to view and…

  • CVE-2017-4014HigMay 17, 2017
    risk 0.52cvss 8.0epss 0.01

    Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view, add, and remove users via modification of the HTTP request.

  • CVE-2024-22250HigFeb 20, 2024
    risk 0.51cvss 7.8epss 0.00

    Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-in could allow a malicious actor with unprivileged local access to a windows operating system can hijack a privileged EAP session when initiated by a privileged domain user on the same system.

  • CVE-2019-4591HigJul 13, 2020
    risk 0.51cvss 7.8epss 0.00

    IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 167451.

  • CVE-2026-56425HigJun 22, 2026
    risk 0.50cvss 8.8epss 0.00

    The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol. The application used the PHP session identifier…

  • CVE-2023-32997HigMay 16, 2023
    risk 0.50cvss 8.8epss 0.01

    Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login.

  • CVE-2023-2105HigApr 15, 2023
    risk 0.50cvss 8.8epss 0.01

    Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

  • CVE-2019-17563HigDec 23, 2019
    risk 0.50cvss 7.5epss 0.11

    When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the…

  • CVE-2019-1807HigMay 3, 2019
    risk 0.50cvss 7.6epss 0.01

    A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user session. The vulnerability exists due to the affected application not invalidating an…

  • CVE-2018-17199HigJan 30, 2019
    risk 0.50cvss 7.5epss 0.21

    In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.