Detailedlikelihood: Mediumseverity: HighDraft
CAPEC-61Session Fixation
Abstraction
Detailed
Status
Draft
Likelihood
Medium
Severity
High
Description
The attacker induces a client to establish a session with the target software using a session identifier provided by the attacker. Once the user successfully authenticates to the target software, the attacker uses the (now privileged) session identifier in their own transactions. This attack leverages the fact that the target software either relies on client-generated session identifiers or maintains the same session identifiers after privilege elevation.
Related weaknesses· 3
Related attack patterns· 1
Exploits3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Session Fixationcwe-384 | 100% | live |
| Weakness | Incorrect Permission Assignment for Critical Resourcecwe-732 | 100% | live |
| Weakness | Improper Control of a Resource Through its Lifetimecwe-664 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.