← Back
CWE-613

568 CVEs • Abstraction: Base

Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

JSON object

Loading...

CVEs (568)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Octobercms
1October
Jun 17, 2026
Feb 5, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the intended Auth/Manager.php authentication beh...Show more
An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the intended Auth/Manager.php authentication behavior but, admittedly, is only relevant if an old session ID is known to an attacker.Show less
1Hcltechsw
1Onetest Performance
Jun 17, 2026
Feb 4, 2021
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID.
1Files
1Fat Client
Jun 17, 2026
Jan 19, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Files.com Fat Client 3.3.6 allows authentication bypass because the client continues to have access after a logout and a removal of a login profile.
1Combodo
1Itop
Jun 17, 2026
Jan 13, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which leads to a possibility to steal user session. This is fixed in versions...Show more
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which leads to a possibility to steal user session. This is fixed in versions 2.7.2 and 3.0.0.Show less
1Combodo
1Itop
Jun 17, 2026
Jan 13, 2021
N/A· v4
6.8 MEDIUM· v3
3.5 LOW· v2
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed...Show more
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed in versions 2.7.2 and 3.0.0.Show less
1Rest/json Project
1Rest/json
Nov 21, 2024
Jan 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
1Lanatmservice
1M3 Atm Monitoring System
Jun 17, 2026
Dec 10, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.
1Ibm
1Cloud Pak For Security
Jun 17, 2026
Nov 30, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow an authenticated user to obtain sensitive information from the previous session. IBM X-Force ID: 186789.
1Gitlab
1Gitaly
Jun 17, 2026
Nov 17, 2020
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.
1Anuko
1Time Tracker
Jun 17, 2026
Nov 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.
1Microweber
1Microweber
Jun 17, 2026
Nov 9, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and rema...Show more
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.Show less
1Microweber
1Microweber
Jul 9, 2026
Nov 9, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Microweber v1.1.18 is affected by no session expiry after log-out.
1Immuta
1Immuta
Jun 17, 2026
Nov 5, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.
1Cyberark
1Privileged Session Manager
Jun 17, 2026
Oct 28, 2020
N/A· v4
2.6 LOW· v3
2.1 LOW· v2
CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.
1Getgophish
1Gophish
Jun 17, 2026
Oct 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.
1Citadel
1Webcit
Jun 17, 2026
Oct 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in users' sessions. NOTE: this was reported to the vendor in a publicly archived "Mu...Show more
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in users' sessions. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.Show less
1Sparksolutions
1Spree
Jun 17, 2026
Oct 20, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is des...Show more
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory.Show less
1Juniper
1Junos Os Evolved
Jun 17, 2026
Oct 16, 2020
N/A· v4
6.6 MEDIUM· v3
7.2 HIGH· v2
The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the console cable is disconnected. This could allow a malicious attacker wi...Show more
The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the console cable is disconnected. This could allow a malicious attacker with physical access to the console the ability to resume a previous interactive session and possibly gain administrative privileges. This issue affects all Juniper Networks Junos OS Evolved versions after 18.4R1-EVO, prior to 20.2R1-EVO.Show less
1Sap
1Commerce Cloud
Jun 17, 2026
Oct 15, 2020
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with username/passphrase credent...Show more
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with username/passphrase credentials. The user can change their own passphrase, but this does not invalidate active sessions that the user may have with SAP Commerce Cloud web applications, which gives an attacker the opportunity to reuse old session credentials, resulting in Insufficient Session Expiration.Show less
1Ibm
1Security Access Manager Appliance
Jun 17, 2026
Oct 14, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 179358.