CWE-384
412 CVEs • Abstraction: Compound
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
CVEs (412)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Honeywell 7Enterprise Dvr Firmware Fusion Iv Rev C FirmwareMaxpro Nvr Hybrid Se Firmware+4 moreMay 13, 2026 Sep 11, 2017 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request t...Show more |
1Cisco 1Prime Lan Management Solution May 13, 2026 Sep 7, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack another user's administrative session, aka a Session Fixation Vulnerability. The...Show more |
Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attackers to hijack web sessions via unspecified vectors. |
2Debian Simplesamlphp2Debian Linux SimplesamlphpMay 13, 2026 Sep 1, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity...Show more |
1Simplesamlphp 1Simplesamlphp May 13, 2026 Sep 1, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by l...Show more |
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter. |
1Rest Client Project 1Rest Client May 13, 2026 Aug 9, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect. |
Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack web sessions via a session id. |
IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an attacker to hijack a valid user's session. IBM X-Force ID: 120257 |
A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sess...Show more |
ubuntu-image 1.0 before 2017-07-07, when invoked as non-root, creates files in the resulting image with the uid of the invoking user. When the resulting image is booted, a local attacker with the same uid as the image cr...Show more |
Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectors. |
1Pivotal Software 3Cloud Foundry Cf Release Cloud Foundry UaaCloud Foundry Uaa ReleaseMay 13, 2026 Jun 13, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v2.0.0 - v2.7.4.12 & v3.0.0 - v3.11.0, and UAA bosh release v26 & earlier versions. UAA is vuln...Show more |
1Mcafee 1Network Data Loss Prevention May 13, 2026 May 17, 2017 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view, add, and remove users via modification of the HTTP request. |
Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file. |
3Clusterlabs FedoraprojectRedhat3Enterprise Linux FedoraPcsMay 13, 2026 Apr 21, 2017 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 Session fixation vulnerability in pcsd in pcs before 0.9.157. |
Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer correspondi...Show more |
1Ibm 1Financial Transaction Manager May 13, 2026 Apr 14, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293. |
In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under s...Show more |