CWE-384
412 CVEs • Abstraction: Compound
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
CVEs (412)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Hazelcast 2Hazelcast Hazelcast JetJun 17, 2026 Dec 29, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Haze...Show more |
An issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can log back into a victim's account after the victim logged out - /LMS/LM/#main can be used for this. Th...Show more |
An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as that user. This issue...Show more |
1Niceforyou 1Linear Emerge E3 Access Control Firmware Jun 17, 2026 Dec 13, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a cross-site scripting (XSS) vulnerability which is chained with a local session fixation...Show more |
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to ses...Show more |
An issue was discovered in Appalti & Contratti 9.12.2. It allows Session Fixation. When a user logs in providing a JSESSIONID cookie that is issued by the server at the first visit, the cookie value is not updated after...Show more |
An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is possible for an attacker to trick users into opening an authenticated user session for a session identi...Show more |
Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user. |
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 does not issue a new session ID upon successful OAuth authentication. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+. |
VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token. |
1Siemens 27kg9501 0aa01 2aa1 Firmware 7kg9501 0aa31 2aa1 FirmwareJun 17, 2026 Nov 8, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V...Show more |
1Phppointofsale 1Php Point Of Sale Jun 17, 2026 Oct 31, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2
The application was vulnerable to a session fixation that could be used hijack accounts.
|
Session fixation and insufficient session expiration vulnerabilities allow an attacker to perfom session hijacking attacks against users. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0. |
1Siemens 367kg8500 0aa00 0aa0 Firmware 7kg8500 0aa00 2aa0 Firmware7kg8500 0aa10 0aa0 Firmware+33 moreJun 17, 2026 Oct 11, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA00-2AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA10-0AA0) (All versions < V3.10), SICAM P850 (7...Show more |
1Ibm 1Sterling Partner Engagement Manager Jun 17, 2026 Oct 10, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM Sterling Partner Engagement Manager 2.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 229704. |
1Tacitine 2En6200 Prime Quad 100 Firmware En6200 Prime Quad 35 FirmwareJun 17, 2026 Sep 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based...Show more |
Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7. |
Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue. |
In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation. |
Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin...Show more |