VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 15 of 31
  • CVE-2025-14810MedMar 25, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after privileges have been modified which could allow an authenticated user to retain access to sensitive information. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CWE: CWE-613:…

  • CVE-2025-36377MedFeb 17, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.

  • CVE-2025-36376MedFeb 17, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.

  • CVE-2025-27898MedFeb 17, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 does not invalidate session after a timeout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2024-43181MedFeb 4, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2025-36065MedJan 20, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.

  • CVE-2025-36063MedJan 20, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2025-3930MedOct 16, 2025
    risk 0.41cvss epss 0.01

    Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, which allows an attacker who has stolen or intercepted the token to freely reuse it until its expiration date (which is set to 30 days by default, but can be…

  • CVE-2023-49881MedOct 1, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2025-55162MedSep 3, 2025
    risk 0.41cvss 6.3epss 0.00

    Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In versions below 1.32.10 and 1.33.0 through 1.33.6, 1.34.0 through 1.34.4 and 1.35.0, insufficient Session Expiration in the Envoy OAuth2 filter leads to failed…

  • CVE-2025-33005MedJun 1, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2024-22351MedApr 23, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2024-45651MedApr 18, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.

  • CVE-2024-49825MedApr 14, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2024-56351MedDec 20, 2024
    risk 0.41cvss 6.3epss 0.00

    In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles

  • CVE-2024-52311MedNov 9, 2024
    risk 0.41cvss 6.3epss 0.00

    Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired.

  • CVE-2024-38315MedSep 16, 2024
    risk 0.41cvss 6.3epss 0.00

    IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

  • CVE-2024-35220HigMay 21, 2024
    risk 0.41cvss 7.4epss 0.00

    @fastify/session is a session plugin for fastify. Requires the @fastify/cookie plugin. When restoring the cookie from the session store, the `expires` field is overriden if the `maxAge` field was set. This means a cookie is never correctly detected as expired and thus expired…

  • CVE-2023-40695MedMay 3, 2024
    risk 0.41cvss 6.3epss 0.00

    IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 264938.

  • CVE-2024-22358MedApr 12, 2024
    risk 0.41cvss 6.3epss 0.00

    IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. …