← Back
CWE-384

412 CVEs • Abstraction: Compound

Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

JSON object

Loading...

CVEs (412)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Eq 3
2Ccu2 Firmware
Ccu3 Firmware
Jun 17, 2026
Jul 10, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAutoLogin) can be achieved by continuing to use a session ID after a logout, aka HMCCU-154.
1Ibm
1Security Access Manager
Jun 17, 2026
Jun 25, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. I...Show more
IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 158515.Show less
1Siemens
1Logo!8 Firmware
Jun 17, 2026
Jun 12, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx), SIEMENS LOGO!8 (6ED1052-xyy08-0BA0 FS:01 / Firmware version < V1.82.02). The integrated...Show more
A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx), SIEMENS LOGO!8 (6ED1052-xyy08-0BA0 FS:01 / Firmware version < V1.82.02). The integrated webserver does not invalidate the Session ID upon user logout. An attacker that successfully extracted a valid Session ID is able to use it even after the user logs out. The security vulnerability could be exploited by an attacker in a privileged network position who is able to read the communication between the affected device and the user or by an attacker who is able to obtain valid Session IDs through other means. The user must invoke a session to the affected device. At the time of advisory publication no public exploitation of this security vulnerability was known.Show less
1Pydio
1Pydio
Jun 17, 2026
May 31, 2019
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the response body, enabling scripts to get access to its value. This identifier can be reused by an attacker to...Show more
The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the response body, enabling scripts to get access to its value. This identifier can be reused by an attacker to impersonate a user and perform actions on behalf of him/her (if the session is still active).Show less
1Cisco
1Umbrella
Jun 17, 2026
May 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user session. The vulnerability...Show more
A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user session. The vulnerability exists due to the affected application not invalidating an existing session when a user authenticates to the application and changes the users credentials via another authenticated session. An attacker could exploit this vulnerability by using a separate, authenticated, active session to connect to the application through the web UI. A successful exploit could allow the attacker to maintain access to the dashboard via an authenticated user's browser session. Cisco has addressed this vulnerability in the Cisco Umbrella Dashboard. No user action is required.Show less
1Bpcbt
1Smartvista
Nov 21, 2024
Apr 30, 2019
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.
1Zohocorp
1Servicedesk Plus
Jun 17, 2026
Apr 24, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the...Show more
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.Show less
2Ivanti
Pulsesecure
3Connect Secure
Pulse Connect SecurePulse Secure Desktop Client
Jun 17, 2026
Apr 12, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end user, a related issue to CVE-2019-1573....Show more
In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end user, a related issue to CVE-2019-1573. (The endpoint would need to be already compromised for exploitation to succeed.) This affects Pulse Desktop Client 5.x before Secure Desktop 5.3R7 and Pulse Desktop Client 9.x before Secure Desktop 9.0R3. It also affects (for Network Connect customers) Pulse Connect Secure 8.1 before 8.1R14, 8.3 before 8.3R7, and 9.0 before 9.0R3.Show less
1Axiomsl
1Axiom
Nov 21, 2024
Apr 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier is vulnerable to a Session Fixation attack.
1Ibm
1Security Privileged Identity Manager
Nov 21, 2024
Apr 2, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user t...Show more
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 144411.Show less
1Vmware
1Vcloud Director
Jun 17, 2026
Apr 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and Provider Portals. Successful exploitation of this issue may allow a malicious ac...Show more
VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and Provider Portals. Successful exploitation of this issue may allow a malicious actor to access the Tenant or Provider Portals by impersonating a currently logged in session.Show less
1Atlassian
1Crowd
Nov 21, 2024
Mar 29, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSIONID cookie, to gain access to some of t...Show more
The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSIONID cookie, to gain access to some of the built-in and potentially third party rest resources via a session fixation vulnerability.Show less
1Phoenixcontact
4Fl Nat Smcs 8tx Firmware
Fl Nat Smn 8tx M Dmg FirmwareFl Nat Smn 8tx M Firmware+1 more
Jun 17, 2026
Mar 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered on PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M, and FL NAT SMN 8TX-M-DMG devices. There is unauthorized access to the WEB-UI by attackers arriving from the same source IP add...Show more
An issue was discovered on PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M, and FL NAT SMN 8TX-M-DMG devices. There is unauthorized access to the WEB-UI by attackers arriving from the same source IP address as an authenticated user, because this IP address is used as a session identifier.Show less
1Cloudfoundry
1Stratos
Jun 17, 2026
Mar 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instances using the default embedded SQLite database, a remote authenticated...Show more
Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instances using the default embedded SQLite database, a remote authenticated malicious user can switch sessions to another user with the same session id.Show less
1Cloudfoundry
1Stratos
Jun 17, 2026
Mar 7, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on be...Show more
Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on behalf of that user.Show less
1Ibm
1Security Identity Governance And Intelligence
Nov 21, 2024
Feb 21, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by send...Show more
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 153428.Show less
1Intel
1Data Center Manager
Jun 17, 2026
Feb 18, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Insufficient session authentication in web server for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
1Atlassian
1Crowd
Nov 21, 2024
Feb 13, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulne...Show more
Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.Show less
1Dbninja
1Dbninja
Jun 17, 2026
Feb 11, 2019
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
DbNinja 3.2.7 allows session fixation via the data.php sessid parameter.
1Jenkins
1Github Oauth
Jun 17, 2026
Feb 6, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-aut...Show more
An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.Show less