CWE-384— Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.— MITRE CWE catalog
420 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-384page 5 of 9
- CVE-2021-38869CRITICALCVSS 9.8EG 9.82022-04-27
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.
- CVE-2021-39066HIGHCVSS 8.8EG 8.82022-02-02
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.
- CVE-2021-39290CRITICALCVSS 9.8EG 9.82021-08-23
Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB37…
- CVE-2021-41246MEDIUMCVSS 4.6EG 4.62021-12-09
Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session id and session cookie when user logs in. This behavior open…
- CVE-2021-41268MEDIUMCVSS 6.5EG 6.52021-11-24
Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version 5.3.0, the cookie is not invalidated wh…
- CVE-2021-41553CRITICALCVSS 9.8EG 9.82021-10-05
In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session token that could be already in use by another user. It was therefore possible to access the application through a user w…
- CVE-2021-42073HIGHCVSS 8.2EG 8.22021-11-08
An issue was discovered in Barrier before 2.4.0. An attacker can enter an active session state with the barriers component (aka the server-side implementation of Barrier) simply by supplying a client label that identifies a valid client co…
- CVE-2021-42761CRITICALCVSS 9.0EG 9.82023-02-16
A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow …
- CVE-2021-44151HIGHCVSS 7.5EG 7.52021-12-13
An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can hijack any existing sessions by bruteforcing the 4 hex-character session cookie on the Windows version (the Linux version appears to have 8 char…
- CVE-2021-46279CRITICALCVSS 5.8EG 9.82022-10-24
Session fixation and insufficient session expiration vulnerabilities allow an attacker to perfom session hijacking attacks against users. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.
- CVE-2022-1849MEDIUMCVSS 5.4EG 5.42022-05-24
Session Fixation in GitHub repository filegator/filegator prior to 7.8.0.
- CVE-2022-22551HIGHCVSS 8.3EG 8.32022-01-21
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.
- CVE-2022-22681HIGHCVSS 8.1EG 8.12022-07-06
Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass security constraint via unspecified vectors.
- CVE-2022-22922CRITICALCVSS 9.8EG 9.82022-02-18
TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable session keys, allowing attackers to gain administrative privileges.
- CVE-2022-24444MEDIUMCVSS 6.5EG 6.52022-06-28
Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
- CVE-2022-24745MEDIUMCVSS 4.8EG 4.82022-03-09
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inconsistent experienc…
- CVE-2022-24781HIGHCVSS 7.1EG 7.12022-03-24
Geon is a board game based on solving questions about the Pythagorean Theorem. Malicious users can obtain the uuid from other users, spoof that uuid through the browser console and become co-owners of the target session. This issue is patc…
- CVE-2022-24895MEDIUMCVSS 6.3EG 6.32023-02-03
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the rest of session attributes. Because thi…
- CVE-2022-25896MEDIUMCVSS 4.8EG 4.82022-07-01
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.
- CVE-2022-26591HIGHCVSS 7.5EG 7.52022-04-06
FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a crafted GET request.
- CVE-2022-27305HIGHCVSS 8.8EG 8.82022-05-25
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
- CVE-2022-2820HIGHCVSS 7.0EG 8.22022-08-15
Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2.
- CVE-2022-2997HIGHCVSS 8.0EG 8.02022-08-25
Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.
- CVE-2022-30605HIGHCVSS 8.8EG 8.82022-08-22
A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to…
- CVE-2022-30769MEDIUMCVSS 4.6EG 4.62022-11-15
Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user.
- CVE-2022-31689CRITICALCVSS 9.8EG 9.82022-11-09
VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.
- CVE-2022-31798MEDIUMCVSS 6.1EG 6.12022-08-25
Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user a…
- CVE-2022-31888HIGHCVSS 8.8EG 8.82023-04-05
Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.
- CVE-2022-3269CRITICALCVSS 9.8EG 9.82022-09-23
Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.
- CVE-2022-33927MEDIUMCVSS 5.4EG 6.52022-08-10
Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by taking advantage of a user with multiple active sessions in order to hijack a user's session.
- CVE-2022-34334MEDIUMCVSS 6.5EG 6.52022-10-10
IBM Sterling Partner Engagement Manager 2.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 229704.
- CVE-2022-34536HIGHCVSS 7.5EG 7.52022-07-19
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows attackers to access the core log file and perform session hijacking via a crafted session token.
- CVE-2022-36437CRITICALCVSS 9.1EG 9.12022-12-29
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are …
- CVE-2022-38054CRITICALCVSS 9.8EG 9.82022-09-02
In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.
- CVE-2022-38369HIGHCVSS 8.8EG 8.82022-09-05
Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
- CVE-2022-38628MEDIUMCVSS 6.1EG 6.12022-12-13
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a cross-site scripting (XSS) vulnerability which is chained with a local session fixation. This vulnerabilit…
- CVE-2022-3916MEDIUMCVSS 6.8EG 6.82023-09-20
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root an…
- CVE-2022-40226HIGHCVSS 7.5EG 8.12022-10-11
A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA00-2AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA10-0AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA10-2AA0) …
- CVE-2022-40293CRITICALCVSS 9.8EG 9.82022-10-31
The application was vulnerable to a session fixation that could be used hijack accounts.
- CVE-2022-40630CRITICALCVSS 6.5EG 9.82022-09-23
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based management interfac…
- CVE-2022-40916CRITICALCVSS 9.8EG 9.82025-02-06
Tiny File Manager v2.4.7 and below is vulnerable to session fixation.
- CVE-2022-4231MEDIUMCVSS 4.2EG 5.42022-11-30
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to session fixiation. The…
- CVE-2022-43398HIGHCVSS 7.5EG 8.82022-11-08
A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50). Affected dev…
- CVE-2022-43529MEDIUMCVSS 4.6EG 5.42023-01-05
A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote attacker to persist a session after a password reset or similar session clearing event. Successful exploitation of thi…
- CVE-2022-43687MEDIUMCVSS 5.4EG 5.42022-11-14
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 does not issue a new session ID upon successful OAuth authentication. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
- CVE-2022-44007HIGHCVSS 8.8EG 8.82022-11-16
An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is possible for an attacker to trick users into opening an authenticated user session for a session identifier known to the a…
- CVE-2022-44017HIGHCVSS 7.5EG 7.52022-12-25
An issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can log back into a victim's account after the victim logged out - /LMS/LM/#main can be used for this. This is due to the cr…
- CVE-2022-44788MEDIUMCVSS 6.5EG 6.52022-11-21
An issue was discovered in Appalti & Contratti 9.12.2. It allows Session Fixation. When a user logs in providing a JSESSIONID cookie that is issued by the server at the first visit, the cookie value is not updated after a successful login.
- CVE-2022-46480HIGHCVSS 8.1EG 8.12023-12-05
Incorrect Session Management and Credential Re-use in the Bluetooth LE stack of the Ultraloq UL3 2nd Gen Smart Lock Firmware 02.27.0012 allows an attacker to sniff the unlock code and unlock the device whilst within Bluetooth range.
- CVE-2023-0897HIGHCVSS 8.8EG 8.82023-10-26
Sielco PolyEco1000 is vulnerable to a session hijack vulnerability due to the cookie being vulnerable to a brute force attack, lack of SSL, and the session being visible in requests.
Map vulnerabilities like CWE-384 to your infrastructure
EchelonGraph correlates every CVE — across CWE-384 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →