← Back
CWE-384

424 CVEs • Abstraction: Compound

Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

JSON object

Loading...

CVEs (424)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Halvotec
1Raquest
Jun 17, 2026
Mar 16, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0.
1Ibm
1Cloud Automation Manager
Jun 17, 2026
Mar 16, 2020
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
IBM Cloud Automation Manager 3.2.1.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may...Show more
IBM Cloud Automation Manager 3.2.1.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 168645.Show less
1Mitsubishielectric
1Iu1 1m20 D Firmware
Jun 17, 2026
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not properly manage sessions, which allows remote attackers to stop the network functions...Show more
TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not properly manage sessions, which allows remote attackers to stop the network functions or execute malware via a specially crafted packet.Show less
1Humaxdigital
1Hga12r 02 Firmware
Jun 17, 2026
Mar 5, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking.
1Western Digital
2Ibi
My Cloud Home
Jun 17, 2026
Feb 20, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation.
1Keplerproject
1Cgilua
Nov 21, 2024
Feb 6, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-28...Show more
The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.Show less
1Keplerproject
1Cgilua
Nov 21, 2024
Feb 6, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.
2Fedoraproject
Mediawiki
2Fedora
Mediawiki
Nov 21, 2024
Feb 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to...Show more
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.Show less
1Ibm
1Infosphere Information Server
Nov 21, 2024
Feb 5, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
5.9 MEDIUM· v3
3.2 LOW· v2
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
1Powauth
1Pow
Jun 17, 2026
Jan 9, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, such as Redis or a database. Cookie store...Show more
In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, such as Redis or a database. Cookie store, which is used in most Phoenix apps, doesn't have this vulnerability.Show less
2Infinispan
Redhat
2Infinispan
Jboss Data Grid
Jun 17, 2026
Jan 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.
5Apache
CanonicalDebian+2 more
11Agile Engineering Data Management
Debian LinuxHyperion Infrastructure Technology+8 more
Jun 17, 2026
Dec 23, 2019
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too...Show more
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.Show less
1Dell
1Rsa Identity Governance And Lifecycle
Jun 17, 2026
Dec 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vu...Show more
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session.Show less
1Magento
1Magento
Jun 17, 2026
Nov 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can leverage a guest session id value following a succes...Show more
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can leverage a guest session id value following a successful login to gain access to customer account index page.Show less
1Apache
1Impala
Jun 17, 2026
Nov 5, 2019
N/A· v4
7.5 HIGH· v3
4.6 MEDIUM· v2
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially b...Show more
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization and audit mechanisms. Session and query IDs are unique and random, but have not been documented or consistently treated as sensitive secrets. Therefore they may be exposed in logs or interfaces. They were also not generated with a cryptographically secure random number generator, so are vulnerable to random number generator attacks that predict future IDs based on past IDs. Impala deployments with Apache Sentry or Apache Ranger authorization enabled may be vulnerable to privilege escalation if an authenticated attacker is able to hijack a session or query from another authenticated user with privileges not assigned to the attacker. Impala deployments with audit logging enabled may be vulnerable to incorrect audit logging as a user could undertake actions that were logged under the name of a different authenticated user. Constructing an attack requires a high degree of technical sophistication and access to the Impala system as an authenticated user.Show less
1Typo3
1Typo3
Nov 21, 2024
Nov 5, 2019
N/A· v4
6.5 MEDIUM· v3
9.4 HIGH· v2
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.
1Oxid Esales
1Eshop
Jun 17, 2026
Nov 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Vers...Show more
An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Version: 4.9.x-4.10.x. By using a specially crafted URL, users with administrative rights could unintentionally grant unauthorized users access to the admin panel via session fixation.Show less
1Clonos
1Clonos
Jun 17, 2026
Oct 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.
1Eq 3
1Homematic Ccu3 Firmware
Jun 17, 2026
Oct 17, 2019
N/A· v4
7.3 HIGH· v3
4.9 MEDIUM· v2
eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the victim. After the victim logs in to the session, the attacker can use that session. The attacker could...Show more
eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the victim. After the victim logs in to the session, the attacker can use that session. The attacker could create SSH logins after a valid session and easily compromise the system.Show less