CWE-384
424 CVEs • Abstraction: Compound
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
CVEs (424)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0. |
IBM Cloud Automation Manager 3.2.1.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may...Show more |
1Mitsubishielectric 1Iu1 1m20 D Firmware Jun 17, 2026 Mar 16, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not properly manage sessions, which allows remote attackers to stop the network functions...Show more |
1Humaxdigital 1Hga12r 02 Firmware Jun 17, 2026 Mar 5, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking. |
1Western Digital 2Ibi My Cloud HomeJun 17, 2026 Feb 20, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation. |
The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-28...Show more |
The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875. |
2Fedoraproject Mediawiki2Fedora MediawikiNov 21, 2024 Feb 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to...Show more |
1Ibm 1Infosphere Information Server Nov 21, 2024 Feb 5, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability |
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset. |
In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, such as Redis or a database. Cookie store...Show more |
2Infinispan Redhat2Infinispan Jboss Data GridJun 17, 2026 Jan 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling. |
5Apache CanonicalDebian+2 more11Agile Engineering Data Management Debian LinuxHyperion Infrastructure Technology+8 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too...Show more |
1Dell 1Rsa Identity Governance And Lifecycle Jun 17, 2026 Dec 18, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vu...Show more |
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can leverage a guest session id value following a succes...Show more |
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially b...Show more |
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session. |
An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Vers...Show more |
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management. |
1Eq 3 1Homematic Ccu3 Firmware Jun 17, 2026 Oct 17, 2019 N/A· v4 7.3 HIGH· v3 4.9 MEDIUM· v2 eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the victim. After the victim logs in to the session, the attacker can use that session. The attacker could...Show more |