CWE-384— Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.— MITRE CWE catalog
424 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-384page 1 of 9
- CVE-1999-0428HIGHCVSS v2 7.5EG 7.51999-03-22
OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.
- CVE-2001-1534LOWCVSS v2 2.1EG 2.12001-12-31
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when…
- CVE-2007-4188HIGHCVSS v2 9.3EG 9.32007-08-08
Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors.
- CVE-2008-3222MEDIUMCVSS v2 5.8EG 5.82008-07-18
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.
- CVE-2009-10007CRITICALCVSS 9.1EG 9.12026-06-09
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a …
- CVE-2010-1434HIGHCVSS 7.5EG 7.52021-06-21
Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hijack an arbitrary session and gain access to sensitive information, which may help in launching further attacks. Joomla! Core versions 1.5.…
- CVE-2010-3671MEDIUMCVSS 6.5EG 6.52019-11-05
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.
- CVE-2013-0507HIGHCVSS 8.1EG 8.12020-02-05
IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability
- CVE-2013-2049HIGHCVSS 7.5EG 7.52018-05-01
Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret.
- CVE-2013-4572HIGHCVSS 7.5EG 7.52020-02-06
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the…
- CVE-2014-10399MEDIUMCVSS 6.1EG 6.12020-02-06
The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.
- CVE-2014-10400MEDIUMCVSS 6.1EG 6.12020-02-06
The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.
- CVE-2014-125048MEDIUMCVSS 6.3EG 6.32023-01-06
A vulnerability, which was classified as critical, has been found in kassi xingwall. This issue affects some unknown processing of the file app/controllers/oauth.js. The manipulation leads to session fixiation. The patch is named e9f0d509e…
- CVE-2014-4789MEDIUMCVSS v2 6.8EG 6.82014-09-10
Session fixation vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote attackers to hijack web sessions via unspecified vectors.
- CVE-2015-1174CRITICALCVSS 9.8EG 9.82017-08-02
Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack web sessions via a session id.
- CVE-2015-1820CRITICALCVSS 9.8EG 9.82017-08-09
REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.
- CVE-2015-4594CRITICALCVSS 9.8EG 9.82017-01-10
eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID.
- CVE-2015-5384HIGHCVSS 8.8EG 8.82019-04-03
AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier is vulnerable to a Session Fixation attack.
- CVE-2016-0721HIGHCVSS 8.1EG 8.12017-04-21
Session fixation vulnerability in pcsd in pcs before 0.9.157.
- CVE-2016-10205HIGHCVSS 7.3EG 7.32017-03-03
Session fixation vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack web sessions via the ZMSESSID cookie.
- CVE-2016-10405CRITICALCVSS 9.8EG 9.82017-09-07
Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attackers to hijack web sessions via unspecified vectors.
- CVE-2016-6040MEDIUMCVSS 5.0EG 5.02017-02-01
IBM Jazz Foundation could allow an authenticated user to take over a previously logged in user due to session expiration not being enforced.
- CVE-2016-6043HIGHCVSS 7.0EG 7.02017-02-01
Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to session expiration not being enforced.
- CVE-2016-6545CRITICALCVSS 9.8EG 9.82018-07-13
Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base64 encoded passwd field on every request. In this implementation, sessions can only be ter…
- CVE-2016-8609LOWCVSS 3.7EG 3.72018-08-01
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclos…
- CVE-2016-8638CRITICALCVSS 9.1EG 9.12017-07-12
A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an…
- CVE-2016-9125CRITICALCVSS 9.8EG 9.82017-03-28
Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, …
- CVE-2016-9574MEDIUMCVSS 5.9EG 5.92018-07-19
nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicket extension and ECDHE-ECDSA.
- CVE-2016-9703LOWCVSS 2.4EG 2.42017-02-01
IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.
- CVE-2016-9981HIGHCVSS 8.1EG 8.12017-08-02
IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an attacker to hijack a valid user's session. IBM X-Force ID: 120257
- CVE-2017-0892LOWCVSS 3.5EG 3.52017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.
- CVE-2017-1000150HIGHCVSS 8.8EG 8.82017-11-03
Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation attacks.
- CVE-2017-10600MEDIUMCVSS 5.9EG 5.92017-07-11
ubuntu-image 1.0 before 2017-07-07, when invoked as non-root, creates files in the resulting image with the uid of the invoking user. When the resulting image is booted, a local attacker with the same uid as the image creator has unintende…
- CVE-2017-10890MEDIUMCVSS 4.6EG 4.62017-11-17
Session management issue in RX-V200 firmware versions prior to 09.87.17.09, RX-V100 firmware versions prior to 03.29.17.09, RX-CLV1-P firmware versions prior to 79.17.17.09, RX-CLV2-B firmware versions prior to 89.07.17.09, RX-CLV3-N firmw…
- CVE-2017-11191HIGHCVSS 8.8EG 8.82017-09-28
FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NO…
- CVE-2017-1152MEDIUMCVSS 4.3EG 4.32017-04-14
IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.
- CVE-2017-11562HIGHCVSS 8.8EG 8.82017-12-19
A Session Fixation Vulnerability exists in the MT4 Networks SenhaSegura Web Application 2.2.23.8 via login_if.php.
- CVE-2017-12225MEDIUMCVSS 6.5EG 6.52017-09-07
A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack another user's administrative session, aka a Session Fixation Vulnerability. The vulnerability is d…
- CVE-2017-12619HIGHCVSS 8.1EG 8.12019-04-23
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone".
- CVE-2017-1270LOWCVSS 3.3EG 3.32017-12-20
IBM Security Guardium 10.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM …
- CVE-2017-12868CRITICALCVSS 9.8EG 9.82017-09-01
The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing c…
- CVE-2017-12873CRITICALCVSS 9.8EG 9.82017-09-01
SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is …
- CVE-2017-12965CRITICALCVSS 9.8EG 9.82017-08-23
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
- CVE-2017-1368MEDIUMCVSS 4.3EG 6.52018-08-06
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by p…
- CVE-2017-14163HIGHCVSS 8.8EG 8.82017-10-31
An issue was discovered in Mahara before 15.04.14, 16.x before 16.04.8, 16.10.x before 16.10.5, and 17.x before 17.04.3. When one closes the browser without logging out of Mahara, the value in the usr_session table is not removed. If someo…
- CVE-2017-14263HIGHCVSS 8.1EG 8.12017-09-11
Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. Th…
- CVE-2017-15304CRITICALCVSS 9.8EG 9.82017-10-15
/bin/login.php in the Web Panel on the Airtame HDMI dongle with firmware before 3.0 allows an attacker to set his own session id via a "Cookie: PHPSESSID=" header. This can be used to achieve persistent access to the admin panel even after…
- CVE-2017-18105HIGHCVSS 8.1EG 8.12019-03-29
The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSIONID cookie, to gain access to some of the built-in and pot…
- CVE-2017-18125HIGHCVSS 7.5EG 7.52018-04-11
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835, SD 845, SD 850, when secure camera is activated it stores captured data in protect…
- CVE-2017-2145MEDIUMCVSS 5.4EG 5.42017-07-07
Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectors.
Map vulnerabilities like CWE-384 to your infrastructure
EchelonGraph correlates every CVE — across CWE-384 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →