CWE-384
424 CVEs • Abstraction: Compound
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
CVEs (424)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Aio Libs 1Aiohttp Session Jul 11, 2025 Jun 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 aio-libs aiohttp-session contains a Session Fixation vulnerability in load_session function for RedisStorage (see: https://github.com/aio-libs/aiohttp-session/blob/master/aiohttp_session/redis_storage.py#L42) that can re...Show more |
2Eclipse Netapp12E Series Santricity Management Plug Ins E Series Santricity Os ControllerE Series Santricity Web Services Proxy+9 moreNov 21, 2024 Jun 22, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSes...Show more |
A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an unauthenticated, local attacker to hijack a valid user session identifi...Show more |
1Broadcom 1Privileged Access Manager Jun 17, 2026 Jun 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions with a specially crafted request. |
A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled. |
1Mcafee 2Network Data Loss Prevention Network Security ManagerNov 21, 2024 Jun 13, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive...Show more |
3Debian FedoraprojectSensiolabs3Debian Linux FedoraSymfonyNov 21, 2024 Jun 13, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard...Show more |
1Tp Link 2Tl Wr840n Firmware Tl Wr841n FirmwareNov 21, 2024 Jun 4, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session...Show more |
ClipperCMS 1.3.3 allows Session Fixation. |
1Amazon 5Echo Dot Firmware Echo FirmwareEcho Plus Firmware+2 moreNov 21, 2024 May 30, 2018 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt feature is designed so that if Alexa does not receive an input within 8 seconds, the device can spea...Show more |
1Ibm 1Security Guardium Big Data Intelligence Nov 21, 2024 May 29, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utiliz...Show more |
Monstra CMS 3.0.4 has a Session Management Issue in the Users tab. A password change at users/1/edit does not invalidate a session that is open in a different browser. |
Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab. A password change at admin/index.php?id=users&action=edit&user_id=1 does not invalidate a session that is open in a different browser. |
In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to session fixation after a user password change. |
1Advantech 4Webaccess Webaccess/nmsWebaccess Dashboard+1 moreNov 21, 2024 May 15, 2018 N/A· v4 6.1 MEDIUM· v3 2.6 LOW· v2 In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and pri...Show more |
An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices. The admin login session cookie is insecurely generated making admin session hijacking possible. When an admin logs in, a session cookie is generate...Show more |
A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentic...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 May 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret. |
Session fixation vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3..4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-CUBE 3.0.7, EC-CUBE 3.0.8, EC-CUBE 3.0.9, EC-CUBE 3.0.10, EC-CUBE 3.0....Show more |
1Cisco 2Adaptive Security Appliance Software Anyconnect Secure Mobility ClientNov 21, 2024 Apr 19, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (SSO) authentication for Cisco AnyConnect Secure Mobility Client for Desktop Platforms, Cisco Adaptive Security Appliance...Show more |