CWE-384
424 CVEs • Abstraction: Compound
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
CVEs (424)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A session fixation vulnerability in J-Web on Junos OS may allow an attacker to use social engineering techniques to fix and hijack a J-Web administrators web session and potentially gain administrative access to the devi...Show more |
IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unauthorized user to conduct a session fixation attack due to clients not being disconnected as they should...Show more |
1Ibm 1Websphere Application Server Jun 17, 2026 Sep 30, 2019 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by improper session validation. IBM X-Force ID: 160950. |
1Lenovo 1Cp Storage Block Firmware Jun 17, 2026 Sep 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmware versions prior to 1908.M. This vulnerability allows session IDs to b...Show more |
SilverStripe through 4.3.3 allows session fixation in the "change password" form. |
1Bd 2Pyxis Enterprise Server Pyxis EsJun 17, 2026 Sep 6, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Pyxis ES Versions 1.3.4 through to 1.6.1 and Pyxis Enterprise Server, with Windows Server Versions 4.4 through 4.12, a vulnerability has been identified where existing access privileges are not restricted in coordinat...Show more |
5Belden NetappSiemens+2 more12E Series Santricity Os Controller Garrettcom Magnum Dx940e FirmwareHirschmann Hios+9 moreJun 17, 2026 Aug 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options. |
1Hp 13par Storeserv Management Console Jun 17, 2026 Aug 9, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. |
1Hp 13par Service Processor Firmware Jun 17, 2026 Aug 9, 2019 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 A remote session reuse vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. |
A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to impersonate another user if they can control the pre-authentication se...Show more |
A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior to 1.9.4.2, Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1...Show more |
IBM Cloud Private 3.1.0, 3.1.1, and 3.1.2 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 162949. |
1Eq 3 2Ccu2 Firmware Ccu3 FirmwareJun 17, 2026 Jul 10, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAutoLogin) can be achieved by continuing to use a session ID after a logout, aka HMCCU-154. |
IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. I...Show more |
A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx), SIEMENS LOGO!8 (6ED1052-xyy08-0BA0 FS:01 / Firmware version < V1.82.02). The integrated...Show more |
The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the response body, enabling scripts to get access to its value. This identifier can be reused by an attacker to...Show more |
A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user session. The vulnerability...Show more |
BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter. |
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the...Show more |
2Ivanti Pulsesecure3Connect Secure Pulse Connect SecurePulse Secure Desktop ClientJun 17, 2026 Apr 12, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end user, a related issue to CVE-2019-1573....Show more |