CWE-1004
CVEs classified under CWE-1004, newest first.
2 CVEsRSS
CVE-2026-53660High· 7.4Open Access Management (OpenAM) is an access management solution
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default, and OAuth and O…
▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.33%via NVD
CVE-2026-57948Medium· 6.8Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.co…
Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.co…
▾ SunlitEPSS 0.20%via NVD