VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (454)

page 9 of 23
  • CVE-2023-32997HigMay 16, 2023
    risk 0.50cvss 8.8epss 0.01

    Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login.

  • CVE-2023-2105HigApr 15, 2023
    risk 0.50cvss 8.8epss 0.01

    Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

  • CVE-2019-1807HigMay 3, 2019
    risk 0.50cvss 7.6epss 0.01

    A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user session. The vulnerability exists due to the affected application not invalidating an…

  • CVE-2018-17199HigJan 30, 2019
    risk 0.50cvss 7.5epss 0.20

    In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

  • CVE-2018-14387HigJul 18, 2018
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes the victim to authenticate against the server using the same session identifier. The attacker can…

  • CVE-2023-52353HigJan 21, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum.

  • CVE-2023-28809HigJun 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and…

  • CVE-2023-30056HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.01

    A session takeover vulnerability exists in FICO Origination Manager Decision Module 4.8.1 due to insufficient protection of the JSESSIONID cookie.

  • CVE-2022-44017HigDec 25, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can log back into a victim's account after the victim logged out - /LMS/LM/#main can be used for this. This is due to the credentials not being cleaned from the…

  • CVE-2022-43398HigNov 8, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50). Affected devices do not renew the session cookie…

  • CVE-2022-40226HigOct 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA00-2AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA10-0AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA10-2AA0) (All versions < V3.10), SICAM P850…

  • CVE-2022-34536HigJul 19, 2022
    risk 0.49cvss 7.5epss 0.01

    Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows attackers to access the core log file and perform session hijacking via a crafted session token.

  • CVE-2022-26591HigApr 6, 2022
    risk 0.49cvss 7.5epss 0.01

    FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a crafted GET request.

  • CVE-2021-31745HigDec 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular…

  • CVE-2010-1434HigJun 21, 2021
    risk 0.49cvss 7.5epss 0.01

    Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hijack an arbitrary session and gain access to sensitive information, which may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and…

  • CVE-2020-5645HigNov 6, 2020
    risk 0.49cvss 7.5epss 0.04

    Session fixation vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version "05.65.00.BD" and earlier, GT1450-QMBDE CoreOS version "05.65.00.BD" and earlier, GT1450-QLBDE CoreOS version "05.65.00.BD" and earlier,…

  • CVE-2020-5654HigNov 2, 2020
    risk 0.49cvss 7.5epss 0.03

    Session fixation vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module First 2 digits of serial number are '01' or…

  • CVE-2020-10714HigSep 23, 2020
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and…

  • CVE-2020-5596HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.02

    TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) does not properly manage sessions, which may allow a remote attacker to stop the network functions of the…

  • CVE-2020-11728HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.