CWE-565
76 CVEs • Abstraction: Base
Reliance on Cookies without Validation and Integrity Checking
The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
CVEs (76)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged to. This meant that certain classes of attacks that took advantage of other theoretical vulnerabili...Show more |
IBM Security Secret Server 10.7 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force I...Show more |
ipa 3.0 does not properly check server identity before sending credential containing cookies |
1Ibm 1Security Guardium Big Data Intelligence Jun 17, 2026 Oct 29, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Fo...Show more |
In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is not set. |
1Ibm 1Websphere Application Server Jun 17, 2026 Sep 30, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information caused by the improper setting of a cookie. IBM X-Force ID: 160951. |
1Nortekcontrol 2Linear Emerge 5000p Firmware Linear Emerge 50p FirmwareJun 17, 2026 Jul 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Linear eMerge 50P/5000P devices allow Authentication Bypass. |
1Cdatatec 1Epon Cpe Wifi Devices Firmware Nov 21, 2024 Jan 3, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies. |
An issue was discovered in LAOBANCMS 2.0. /admin/login.php allows spoofing of the id and guanliyuan cookies. |
PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified cookie, related to pc_head.php, pc_login.php, and pc_login_page.php. |
1Moxa 4Oncell G3110 Hspa T Firmware Oncell G3110 Hspa FirmwareOncell G3150 Hspa T Firmware+1 moreJun 17, 2026 Mar 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only dig...Show more |
1Cloudfoundry 3Capi Release Cf ReleaseRouting ReleaseMay 13, 2026 Jul 17, 2017 N/A· v4 6.6 MEDIUM· v3 6.0 MEDIUM· v2 The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens...Show more |
1Unitrends 1Enterprise Backup May 13, 2026 Apr 12, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login. |
1Digisol 1Dg Hr1400 Router Firmware May 13, 2026 Mar 14, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Base64-encoded session cookie value. |
Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors. |
1V3chat 1V3 Chat Profiles Dating Script Apr 23, 2026 Dec 31, 2008 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1. |