CWE-539: Use of Persistent Cookies Containing Sensitive Information
The web application uses persistent cookies, but the cookies contain sensitive information.
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-39275 — Advantech ADAM-5630 Use of Persistent Cookies Containing Sensitive Information
- CVE-2026-24318 — Insecure Session Management vulnerability in SAP BusinessObjects Business Intelligence Platform
- CVE-2025-52633 — HCL AION is susceptible to Missing Content-Security-Policy
- CVE-2026-35192 — Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST
Recently published
- CVE-2026-35192 — Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST
- CVE-2026-24318 — Insecure Session Management vulnerability in SAP BusinessObjects Business Intelligence Platform
- CVE-2025-52633 — HCL AION is susceptible to Missing Content-Security-Policy
- CVE-2024-39275 — Advantech ADAM-5630 Use of Persistent Cookies Containing Sensitive Information