IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker t
Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the sa
PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the sa
Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same aft
Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router u
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for
A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate th
Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a sessi
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst
The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful t
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorizat
Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a s
Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777
Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/
FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSIO
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled
EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a s
A vulnerability has been found in SourceCodester Prison Management System 1.0. The impacted element is an unknown functi
WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function
Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Spa
Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-
Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not disallow the session
A flaw has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont
HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carr
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby S
Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Session Fi
Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affect
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not r
docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the applic
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regen
Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatica
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 aut
All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predef
ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bar
EVerest is an EV charging software stack. In all versions up to and including 2025.12.1, the default value for `terminat
GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.
Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument
A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerab
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 p
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the u
QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same
KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid
Frequently Asked Questions
What is CWE-384?
CWE-384 (CWE-384) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-384?
There are 55 CVE records associated with CWE-384 in our database. Of these, 10 are critical severity, 11 are high severity, and 25 are medium severity.
How can I protect against CWE-384 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-384 using AI-powered security agents.
Detect CWE-384 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-384 vulnerabilities across your infrastructure.
Get Started