CWE-384
424 CVEs • Abstraction: Compound
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
CVEs (424)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation. |
Session Fixation in GitHub repository filegator/filegator prior to 7.8.0. |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Apr 27, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341. |
1Bbraun 2Datamodule Compactplus SpacecomJun 17, 2026 Apr 14, 2022 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sess...Show more |
FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a crafted GET request. |
Geon is a board game based on solving questions about the Pythagorean Theorem. Malicious users can obtain the uuid from other users, spoof that uuid through the browser console and become co-owners of the target session....Show more |
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inc...Show more |
1Ibm 1Financial Transaction Manager Jun 17, 2026 Feb 2, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040. |
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session. |
1Trendnet 1Tew 827dru Firmware Jun 17, 2026 Dec 30, 2021 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web sessions based on IP address rather than verifying client cookies/session...Show more |
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access ca...Show more |
Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session id and session cookie when user logs in....Show more |
Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version 5.3.0, the cookie is...Show more |
An issue was discovered in Barrier before 2.4.0. An attacker can enter an active session state with the barriers component (aka the server-side implementation of Barrier) simply by supplying a client label that identifie...Show more |
In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session token that could be already in use by another user. It was therefore possible to access the applicati...Show more |
Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie. |
Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 1...Show more |
1Netmodule 1Netmodule Router Software Jun 17, 2026 Aug 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, N...Show more |
1Citrix 3Application Delivery Controller Firmware GatewayNetscaler GatewayJun 17, 2026 Aug 5, 2021 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session. |
1Oracle 112Advanced Networking Option Agile Engineering Data ManagementAgile Plm+109 moreAug 25, 2026 Jul 21, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker...Show more |