Falhas do tipo CWE-384

253 resultados

Fixação de Sessão

Fraqueza onde um atacante força a vítima a usar um identificador de sessão conhecido e controlado pelo atacante, em vez de receber um novo ID gerado pela aplicação. Após a vítima autenticar-se, o atacante reutiliza esse ID fixo para acessar a conta com os privilégios da vítima.

Exemplo

Um site envia um cookie de sessão (ex: SESSID=abc123) antes do login. O atacante convence a vítima a acessar um link contendo esse SESSID=abc123, depois que a vítima faz login, o atacante usa o mesmo cookie para acessar a conta autenticada da vítima.

Como mitigar

Gere sempre um novo ID de sessão após autenticação bem-sucedida, descartando qualquer ID anterior. Valide e resete a sessão no servidor a cada mudança de privilégio (login/logout). Use flags seguras no cookie: HttpOnly, Secure e SameSite.

CVE-2025-46605MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixatiEPSS 0.3%CVE-2023-47798MEDIUMAccount lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsuEPSS 0.3%CVE-2026-30224MEDIUMOliveTin: Session Fixation - Logout Fails to Invalidate Server-Side SessionEPSS 0.3%CVE-2026-33492HIGHAVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session RegenerationEPSS 0.3%CVE-2025-10228HIGHSession Hijacking in Rolantis Information Technologies' AgentisEPSS 0.3%CVE-2026-61592HIGHdjust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)EPSS 0.3%CVE-2025-26658MEDIUMBroken Authentication in SAP Business One (Service Layer)EPSS 0.3%CVE-2021-32088CRITICALAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to EPSS 0.3%CVE-2026-18527CRITICALIBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].EPSS 0.3%CVE-2023-50941MEDIUMIBM PowerSC session fixationEPSS 0.3%CVE-2025-64100MEDIUMCKAN Vulnerable to Session Cookie FixationEPSS 0.3%CVE-2026-23796MEDIUMSession Fixation in Quick.CartEPSS 0.3%CVE-2024-42207MEDIUMHCL iAutomate is affected by a session fixation vulnerabilityEPSS 0.3%CVE-2026-56224MEDIUMCapgo - Login CSRF and Session Fixation via URL Query ParametersEPSS 0.3%CVE-2026-64857MEDIUMtirreno has Session Fixation in Login AuthenticationEPSS 0.3%CVE-2026-30808HIGHSession Fixation in Authentication leads to Session HijackingEPSS 0.3%CVE-2023-44400MEDIUMUptime Kuma has Persistentent User Sessions EPSS 0.3%CVE-2026-82355MEDIUMApache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixationEPSS 0.3%CVE-2019-18946MEDIUMSession fixationEPSS 0.3%CVE-2023-49804MEDIUMUptime Kuma Password Change VulnerabilityEPSS 0.3%