CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

509 vulnerabilities with CWE-613
CVE-2026-24667 MEDIUM
Open eClass <4.2 - Info Disclosure
CVSS 5.0
CVE-2026-24472 MEDIUM
Hono <4.11.7 - Info Disclosure
CVSS 5.3
CVE-2025-12624 MEDIUM
Improper Token Invalidation in WSO2 Identity Server Allows Access After Account Lock
CVSS 6.0
CVE-2025-57735 CRITICAL
Apache Airflow: Airflow Logout Not Invalidating JWT
CVSS 9.1
CVE-2025-66483 MEDIUM
Multiple vulnerabilities have been addressed in IBM Aspera Shares
CVSS 6.3
CVE-2025-55264 MEDIUM
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change
CVSS 5.5
CVE-2025-14810 MEDIUM
IBM InfoSphere Information Server is vulnerable due to insufficient session expiration
CVSS 6.3
CVE-2025-15553 HIGH
Insecure Logout Functionality in Truesec LAPSWebUI
CVSS 7.1
CVE-2025-15552 HIGH
Long Session Lifetime in Truesec LAPSWebUI
CVSS 7.8
CVE-2025-59786 CRITICAL
2N Access Commander <3.4.2 - Auth Bypass
CVSS 9.8
CVE-2025-36377 MEDIUM
IBM Security QRadar EDR 3.12-3.12.23 - Auth Bypass
CVSS 6.3
CVE-2025-36376 MEDIUM
IBM Security QRadar EDR 3.12-3.12.23 - Auth Bypass
CVSS 6.3
CVE-2025-27898 MEDIUM
IBM DB2 Recovery Expert 5.5 IF002 - Auth Bypass
CVSS 6.3
CVE-2025-55705 HIGH
Evmapa EV Charging System - Session Management
CVSS 7.3
CVE-2025-36065 MEDIUM
IBM Sterling Connect < 5.2.0.13 - Insufficient Session Expiration
CVSS 6.3
CVE-2025-36063 MEDIUM
IBM Sterling Connect < 5.2.0.13 - Insufficient Session Expiration
CVSS 6.3
CVE-2025-52661 LOW
Hcltech Aion - Insufficient Session Expiration
CVSS 2.4
CVE-2025-4677 MEDIUM
ABB WebPro SNMP Card PowerValue <1.1.8.K - Info Disclosure
CVSS 6.5
CVE-2025-31962 LOW
Hcltech Bigfix Insights For Vulnerabi... - Insufficient Session Expiration
CVSS 2.0
CVE-2025-68954 MEDIUM
Pterodactyl <1.11.11 - Info Disclosure
CVSS 5.4
CVE-2025-55254 LOW
HCL BigFix Remote Control Lite Web Portal <10.1.0.0326 - RCE
CVSS 3.7
CVE-2025-62329 MEDIUM
Hcltechsw Hcl Devops Deploy - Insufficient Session Expiration
CVSS 5.0
CVE-2025-36360 MEDIUM
IBM Devops Deploy < 8.0.1.11 - Insufficient Session Expiration
CVSS 5.0
CVE-2025-65430 MEDIUM
Allauth < 65.13.0 - Insufficient Session Expiration
CVSS 5.4
CVE-2025-62631 MEDIUM
Fortinet Fortios < 7.4.1 - Insufficient Session Expiration
CVSS 5.6
Details
Vulnerabilities 509