CWE-384
412 CVEs • Abstraction: Compound
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
CVEs (412)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Apache CanonicalDebian+2 more11Agile Engineering Data Management Debian LinuxHyperion Infrastructure Technology+8 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too...Show more |
1Dell 1Rsa Identity Governance And Lifecycle Jun 17, 2026 Dec 18, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vu...Show more |
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can leverage a guest session id value following a succes...Show more |
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially b...Show more |
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session. |
An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Vers...Show more |
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management. |
1Eq 3 1Homematic Ccu3 Firmware Jun 17, 2026 Oct 17, 2019 N/A· v4 7.3 HIGH· v3 4.9 MEDIUM· v2 eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the victim. After the victim logs in to the session, the attacker can use that session. The attacker could...Show more |
A session fixation vulnerability in J-Web on Junos OS may allow an attacker to use social engineering techniques to fix and hijack a J-Web administrators web session and potentially gain administrative access to the devi...Show more |
IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unauthorized user to conduct a session fixation attack due to clients not being disconnected as they should...Show more |
1Ibm 1Websphere Application Server Jun 17, 2026 Sep 30, 2019 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by improper session validation. IBM X-Force ID: 160950. |
1Lenovo 1Cp Storage Block Firmware Jun 17, 2026 Sep 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmware versions prior to 1908.M. This vulnerability allows session IDs to b...Show more |
SilverStripe through 4.3.3 allows session fixation in the "change password" form. |
1Bd 2Pyxis Enterprise Server Pyxis EsJun 17, 2026 Sep 6, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Pyxis ES Versions 1.3.4 through to 1.6.1 and Pyxis Enterprise Server, with Windows Server Versions 4.4 through 4.12, a vulnerability has been identified where existing access privileges are not restricted in coordinat...Show more |
5Belden NetappSiemens+2 more12E Series Santricity Os Controller Garrettcom Magnum Dx940e FirmwareHirschmann Hios+9 moreJun 17, 2026 Aug 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options. |
1Hp 13par Storeserv Management Console Jun 17, 2026 Aug 9, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. |
1Hp 13par Service Processor Firmware Jun 17, 2026 Aug 9, 2019 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 A remote session reuse vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. |
A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to impersonate another user if they can control the pre-authentication se...Show more |
A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior to 1.9.4.2, Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1...Show more |
IBM Cloud Private 3.1.0, 3.1.1, and 3.1.2 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 162949. |