CWE-539
8 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-539page 1 of 1
- CVE-2021-27463MEDIUMCVSS 5.3EG 5.32021-05-20
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications utilize persistent cookies where the session cookie attribute is not properly invalidated, allowing an attacker to i…
- CVE-2023-30861HIGHCVSS 7.5EG 7.52023-05-02
Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxy to other clients. If the proxy also ca…
- CVE-2024-39275HIGHCVSS 8.0EG 8.02024-09-27
Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the s…
- CVE-2025-25613HIGHCVSS 7.5EG 6.52025-11-20
FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for their web based administrative application containing userna…
- CVE-2025-27673CRITICALCVSS 9.1EG 9.12025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cookie Returned in Response Body OVE-20230524-0017.
- CVE-2025-52633LOWCVSS 3.1EG 3.12026-02-03
HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persistent cookies may increase the risk of unauthorized access if the cookies are intercepted or co…
- CVE-2026-24318MEDIUMCVSS 4.2EG 4.22026-04-14
Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse them to gain unauthorized access to a victim�s session. I…
- CVE-2026-35192MEDIUMCVSS 6.5EG 6.52026-05-05
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that us…
Map vulnerabilities like CWE-539 to your infrastructure
EchelonGraph correlates every CVE — across CWE-539 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →