CWE-384— Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.— MITRE CWE catalog
420 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-384page 4 of 9
- CVE-2020-11728HIGHCVSS 7.5EG 7.52020-04-15
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can imperso…
- CVE-2020-11729CRITICALCVSS 9.8EG 9.82020-04-15
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.
- CVE-2020-12258CRITICALCVSS 9.1EG 9.12020-05-18
rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPSESSID. Also, an attacker can exploit this vulnerability in conjunction with CVE-2020-12256…
- CVE-2020-12467MEDIUMCVSS 6.5EG 6.52020-04-29
Subrion CMS 4.2.1 allows session fixation via an alphanumeric value in a session cookie.
- CVE-2020-13229HIGHCVSS 8.8EG 8.82020-06-02
An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi URI, because it is an authentication token.
- CVE-2020-15018MEDIUMCVSS 6.5EG 6.52020-06-24
playSMS through 1.4.3 is vulnerable to session fixation.
- CVE-2020-15679HIGHCVSS 7.6EG 7.62022-12-22
An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as that user. This issue is limited to case…
- CVE-2020-15909HIGHCVSS 8.8EG 8.82020-10-19
SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Central JSESSIONID cookie attribute is not checked against multiple sources such as sourceip, MFA claim, etc. as long as t…
- CVE-2020-1762HIGHCVSS 7.0EG 7.02020-04-27
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user s…
- CVE-2020-1993LOWCVSS 3.7EG 3.72020-05-13
The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks, if an attacker is able to control a user's session ID. This issue affects: All PAN-OS 7.…
- CVE-2020-25152HIGHCVSS 6.5EG 8.12022-04-14
A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sessions and escalate p…
- CVE-2020-25198HIGHCVSS 8.8EG 8.82020-12-23
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protections from session fixation, which may allow an attacker to gain access to a session and hijack it by stealing the user’s…
- CVE-2020-35229HIGHCVSS 8.8EG 8.82021-03-10
The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which allows attackers (with access to network tr…
- CVE-2020-35591MEDIUMCVSS 5.4EG 5.42021-02-18
Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the vic…
- CVE-2020-36913MEDIUMCVSS 5.3EG 5.32026-01-06
All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predefined PHP session identifier during the login process. Attackers can forge HTTP GET requests to welcome.php with a manip…
- CVE-2020-4229HIGHCVSS 7.3EG 7.32020-06-05
IBM Worklight/MobileFoundation 8.0.0.0 does not properly invalidate session cookies when a user logs out of a session, which could allow another user to gain unauthorized access to a user's session. IBM X-Force ID: 175211.
- CVE-2020-4243LOWCVSS 3.7EG 3.72020-08-05
IBM Security Identity Governance and Intelligence 5.2.6 Virtual Appliance could allow a remote attacker to obtain sensitive information using man in the middle techniques due to not properly invalidating session tokens. IBM X-Force ID: 175…
- CVE-2020-4291MEDIUMCVSS 4.3EG 4.32020-04-08
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could disclose sensitive information to an unauthorized user due to insufficient timeout functionality in the Web UI. IBM X-Force ID: 176334.
- CVE-2020-4527MEDIUMCVSS 5.9EG 5.92020-07-20
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the Secure flag for the session cookie in TLS mode. By intercepting its transmission within an HTTP session, an attacker…
- CVE-2020-4555MEDIUMCVSS 5.4EG 5.42020-12-21
IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.
- CVE-2020-4954MEDIUMCVSS 5.4EG 5.42021-02-15
IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to bypass authentication restrictions, caused by improper session validation . By using the configuration panel to obtain a valid session using an attacker co…
- CVE-2020-5021MEDIUMCVSS 4.4EG 4.42021-01-08
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a local user to impersonate another user on the system. IBM X-Force ID: 193657.
- CVE-2020-5205MEDIUMCVSS 6.5EG 6.52020-01-09
In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, such as Redis or a database. Cookie store, which is used in …
- CVE-2020-5290MEDIUMCVSS 6.5EG 6.52020-04-01
In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` hash when making a request to the `/verify` endpoint. An attacker team could potentially steal flags by, for example, expl…
- CVE-2020-5543CRITICALCVSS 9.8EG 9.82020-03-16
TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not properly manage sessions, which allows remote attackers to stop the network functions or execute malware …
- CVE-2020-5550HIGHCVSS 8.1EG 8.12020-04-08
Session fixation vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier, and Enterprise Ver. 2.0.1 and earlier allows remote attackers to impersonate a registered user and log in the management console, that may result in information alte…
- CVE-2020-5596HIGHCVSS 7.5EG 7.52020-07-07
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) does not properly manage sessions, which may allow a remote attacker to…
- CVE-2020-5645HIGHCVSS 7.5EG 7.52020-11-06
Session fixation vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version "05.65.00.BD" and earlier, GT1450-QMBDE CoreOS version "05.65.00.BD" and earlier, GT1450-QLBDE CoreOS …
- CVE-2020-5654HIGHCVSS 7.5EG 7.52020-11-02
Session fixation vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module Fir…
- CVE-2020-5894HIGHCVSS 8.1EG 8.12020-05-07
On versions 3.0.0-3.3.0, the NGINX Controller webserver does not invalidate the server-side session token after users log out.
- CVE-2020-6290MEDIUMCVSS 6.3EG 6.32020-07-14
SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID.
- CVE-2020-6302HIGHCVSS 8.1EG 8.12020-09-09
SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequentl…
- CVE-2020-6824LOWCVSS 2.8EG 2.82020-04-24
Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window, revisited the same …
- CVE-2020-8434CRITICALCVSS 9.8EG 9.82020-05-19
Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch 8 has session cookies that are a deterministic function of the username. There is a hard-coded password to supply a PBK…
- CVE-2020-8826HIGHCVSS 7.5EG 7.52020-04-08
As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authentication.
- CVE-2020-8990CRITICALCVSS 9.1EG 9.12020-02-20
Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation.
- CVE-2020-9370CRITICALCVSS 9.1EG 9.12020-03-05
HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking.
- CVE-2021-20151CRITICALCVSS 10.0EG 10.02021-12-30
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web sessions based on IP address rather than verifying client cookies/session tokens/etc. This al…
- CVE-2021-22237MEDIUMCVSS 6.6EG 6.62021-08-25
Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2
- CVE-2021-22927HIGHCVSS 8.1EG 8.12021-08-05
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
- CVE-2021-2351HIGHCVSS 8.3EG 8.32021-07-21
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network acces…
- CVE-2021-29368HIGHCVSS 8.8EG 8.82023-01-20
Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 allows attackers to gain access to arbitrary user sessions.
- CVE-2021-31745HIGHCVSS 7.5EG 7.52021-12-10
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even…
- CVE-2021-32676MEDIUMCVSS 6.5EG 6.52021-06-16
Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Talk before version 9.0.10, 10.0.8 and 11.2.2 did not rotate the session cookie after a successful authentication event. I…
- CVE-2021-32710MEDIUMCVSS 5.9EG 5.92021-06-24
Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2. We recommend to update to the current version 6.3.5.2. You can get the update to 6.3.5.2 regularly via the Auto-Update…
- CVE-2021-33394MEDIUMCVSS 5.4EG 5.42021-05-27
Cubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in, …
- CVE-2021-35046MEDIUMCVSS 6.1EG 6.12021-06-22
A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user session via a crafted session cookie.
- CVE-2021-35948MEDIUMCVSS 5.4EG 5.42021-09-07
Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.
- CVE-2021-36394CRITICALCVSS 9.8EG 9.82023-03-06
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
- CVE-2021-3740MEDIUMCVSS 6.8EG 6.82024-11-15
A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password, allowing old sessions to persist. This can lea…
Map vulnerabilities like CWE-384 to your infrastructure
EchelonGraph correlates every CVE — across CWE-384 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →