CWE-384
424 CVEs • Abstraction: Compound
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
CVEs (424)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2. We recommend to update to the current version 6.3.5.2. You can get the update to 6.3.5.2 regularly...Show more |
A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user session via a crafted session cookie. |
Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hijack an arbitrary session and gain access to sensitive information, which may help in launching further attacks. Joomla!...Show more |
Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Talk before version 9.0.10, 10.0.8 and 11.2.2 did not rotate the session cookie after a successful auth...Show more |
Cubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After t...Show more |
1Versa Networks 1Versa Operating System Nov 21, 2024 May 26, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed after the user successfully logs into the application. Failing to issue a new session ID following...Show more |
1Netgear 2Gs116e Firmware Jgs516pe FirmwareJun 17, 2026 Mar 10, 2021 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which allows attackers (with a...Show more |
1Microfocus 1Solutions Business Manager Jun 17, 2026 Feb 26, 2021 N/A· v4 4.8 MEDIUM· v3 3.8 LOW· v2 Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixation. |
Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a vi...Show more |
1Ibm 1Spectrum Protect Operations Center Jun 17, 2026 Feb 15, 2021 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to bypass authentication restrictions, caused by improper session validation . By using the configuration panel to obtain a valid session u...Show more |
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a local user to impersonate another user on the system. IBM X-Force ID: 193657. |
1Moxa 1Nport Iaw5000a I/o Firmware Jun 17, 2026 Dec 23, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protections from session fixation, which may allow an attacker to gain access to a session and hijack it by st...Show more |
1Ibm 1Financial Transaction Manager Jun 17, 2026 Dec 21, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328. |
Session fixation vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version "05.65.00.BD" and earlier, GT1450-QMBDE CoreOS version "05.65.00.BD" and earlier, G...Show more |
1Mitsubishielectric 5Melsec Iq Rd81dl96 Firmware Melsec Iq Rd81mes96n FirmwareMelsec Iq Rd81opc96 Firmware+2 moreJun 17, 2026 Nov 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Session fixation vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Co...Show more |
1Ibm 1Security Directory Server Jun 17, 2026 Oct 29, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this lin...Show more |
SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Central JSESSIONID cookie attribute is not checked against multiple sources such as sourceip, MFA claim...Show more |
2Netapp Redhat6Codeready Studio Descision ManagerJboss Fuse+3 moreJun 17, 2026 Sep 23, 2020 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat fr...Show more |
SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle att...Show more |
1Ibm 1Security Identity Governance And Intelligence Jun 17, 2026 Aug 5, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 IBM Security Identity Governance and Intelligence 5.2.6 Virtual Appliance could allow a remote attacker to obtain sensitive information using man in the middle techniques due to not properly invalidating session tokens....Show more |