← Back
CWE-384

424 CVEs • Abstraction: Compound

Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

JSON object

Loading...

CVEs (424)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gibbonedu
1Gibbon
Jul 9, 2026
May 25, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
1Filegator
1Filegator
Jun 17, 2026
May 24, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Session Fixation in GitHub repository filegator/filegator prior to 7.8.0.
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Apr 27, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.
1Bbraun
2Datamodule Compactplus
Spacecom
Jun 17, 2026
Apr 14, 2022
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sess...Show more
A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sessions and escalate privileges.Show less
1Fantec
1Mwid25 Ds Firmware
Jun 17, 2026
Apr 6, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a crafted GET request.
1Geon Project
1Geon
Jun 17, 2026
Mar 24, 2022
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Geon is a board game based on solving questions about the Pythagorean Theorem. Malicious users can obtain the uuid from other users, spoof that uuid through the browser console and become co-owners of the target session....Show more
Geon is a board game based on solving questions about the Pythagorean Theorem. Malicious users can obtain the uuid from other users, spoof that uuid through the browser console and become co-owners of the target session. This issue is patched in version 1.1.0. No known workaround exists.Show less
1Shopware
1Shopware
Jun 17, 2026
Mar 9, 2022
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inc...Show more
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inconsistent experiences for guest users. Setups with Varnish are not affected by this issue. This issue has been resolved in version 6.4.8.2. Users unable to upgrade should disable the HTTP Cache.Show less
1Ibm
1Financial Transaction Manager
Jun 17, 2026
Feb 2, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.
1Dell
1Emc Appsync
Jun 17, 2026
Jan 21, 2022
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web sessions based on IP address rather than verifying client cookies/session...Show more
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web sessions based on IP address rather than verifying client cookies/session tokens/etc. This allows an attacker (whether from a different computer, different web browser on the same machine, etc.) to take over an existing session. This does require the attacker to be able to spoof or take over original IP address of the original user's session.Show less
1Pluck Cms
1Pluck
Jun 17, 2026
Dec 10, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access ca...Show more
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.Show less
1Auth0
1Express Openid Connect
Jun 17, 2026
Dec 9, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session id and session cookie when user logs in....Show more
Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session id and session cookie when user logs in. This behavior opens up the application to various session fixation vulnerabilities. Versions `2.5.2` contains a patch for this issue.Show less
1Sensiolabs
1Symfony
Jun 17, 2026
Nov 24, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version 5.3.0, the cookie is...Show more
Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version 5.3.0, the cookie is not invalidated when the user changes their password. Attackers can therefore maintain their access to the account even if the password is changed as long as they have had the chance to login once and get a valid remember me cookie. Starting with version 5.3.12, Symfony makes the password part of the signature by default. In that way, when the password changes, then the cookie is not valid anymore.Show less
1Barrier Project
1Barrier
Jun 17, 2026
Nov 8, 2021
N/A· v4
8.2 HIGH· v3
5.8 MEDIUM· v2
An issue was discovered in Barrier before 2.4.0. An attacker can enter an active session state with the barriers component (aka the server-side implementation of Barrier) simply by supplying a client label that identifie...Show more
An issue was discovered in Barrier before 2.4.0. An attacker can enter an active session state with the barriers component (aka the server-side implementation of Barrier) simply by supplying a client label that identifies a valid client configuration. This label is "Unnamed" by default but could instead be guessed from hostnames or other publicly available information. In the active session state, an attacker can capture input device events from the server, and also modify the clipboard content on the server.Show less
1Archibus
1Web Central
Jun 17, 2026
Oct 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session token that could be already in use by another user. It was therefore possible to access the applicati...Show more
In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session token that could be already in use by another user. It was therefore possible to access the application through a user whose credentials were not known, without any attempt by the testers to modify the application logic. It is also possible to set the value of the session token, client-side, simply by making an unauthenticated GET Request to the Home Page and adding an arbitrary value to the JSESSIONID field. The application, following the login, does not assign a new token, continuing to keep the inserted one, as the identifier of the entire session. This is fixed in all recent versions, such as version 26. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Version 21.3 was officially de-supported by the end of 2020Show less
1Owncloud
1Owncloud
Jun 17, 2026
Sep 7, 2021
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 25, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 1...Show more
Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2Show less
1Netmodule
1Netmodule Router Software
Jun 17, 2026
Aug 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, N...Show more
Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.Show less
1Citrix
3Application Delivery Controller Firmware
GatewayNetscaler Gateway
Jun 17, 2026
Aug 5, 2021
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
1Oracle
112Advanced Networking Option
Agile Engineering Data ManagementAgile Plm+109 more
Aug 25, 2026
Jul 21, 2021
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker...Show more
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).Show less