← Back
CWE-565

76 CVEs • Abstraction: Base

Reliance on Cookies without Validation and Integrity Checking

The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.

JSON object

Loading...

CVEs (76)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Octobercms
1October
Jun 17, 2026
Jul 31, 2020
N/A· v4
6.3 MEDIUM· v3
3.5 LOW· v2
In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged to. This meant that certain classes of attacks that took advantage of other theoretical vulnerabili...Show more
In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged to. This meant that certain classes of attacks that took advantage of other theoretical vulnerabilities in user facing code (nothing exploitable in the core project itself) had a higher chance of succeeding. Specifically, if your usage exposed a way for users to provide unfiltered user input and have it returned to them as an encrypted cookie (ex. storing a user provided search query in a cookie) they could then use the generated cookie in place of other more tightly controlled cookies; or if your usage exposed the plaintext version of an encrypted cookie at any point to the user they could theoretically provide encrypted content from your application back to it as an encrypted cookie and force the framework to decrypt it for them. Issue has been fixed in build 468 (v1.0.468).Show less
1Ibm
1Security Secret Server
Jun 17, 2026
Jan 28, 2020
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM Security Secret Server 10.7 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force I...Show more
IBM Security Secret Server 10.7 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 170044.Show less
1Freeipa
1Freeipa
Nov 21, 2024
Nov 25, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ipa 3.0 does not properly check server identity before sending credential containing cookies
1Ibm
1Security Guardium Big Data Intelligence
Jun 17, 2026
Oct 29, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Fo...Show more
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Force ID: 161210.Show less
1Centreon
1Centreon Vm
Jun 17, 2026
Oct 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is not set.
1Ibm
1Websphere Application Server
Jun 17, 2026
Sep 30, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information caused by the improper setting of a cookie. IBM X-Force ID: 160951.
1Nortekcontrol
2Linear Emerge 5000p Firmware
Linear Emerge 50p Firmware
Jun 17, 2026
Jul 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Linear eMerge 50P/5000P devices allow Authentication Bypass.
1Cdatatec
1Epon Cpe Wifi Devices Firmware
Nov 21, 2024
Jan 3, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.
1Laobancms
1Laobancms
Nov 21, 2024
Nov 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in LAOBANCMS 2.0. /admin/login.php allows spoofing of the id and guanliyuan cookies.
1Picturespro
1Picturespro
Nov 21, 2024
Apr 17, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified cookie, related to pc_head.php, pc_login.php, and pc_login_page.php.
1Moxa
4Oncell G3110 Hspa T Firmware
Oncell G3110 Hspa FirmwareOncell G3150 Hspa T Firmware+1 more
Jun 17, 2026
Mar 5, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only dig...Show more
A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only digits, allowing an attacker to perform a brute force attack bypassing authentication and gaining access to device functions.Show less
1Cloudfoundry
3Capi Release
Cf ReleaseRouting Release
May 13, 2026
Jul 17, 2017
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens...Show more
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.Show less
1Unitrends
1Enterprise Backup
May 13, 2026
Apr 12, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login.
1Digisol
1Dg Hr1400 Router Firmware
May 13, 2026
Mar 14, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Base64-encoded session cookie value.
2Apple
Google
3Chrome
Iphone OsSafari
Apr 29, 2026
Oct 25, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.
1V3chat
1V3 Chat Profiles Dating Script
Apr 23, 2026
Dec 31, 2008
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.