Previous Topic: Some Administration Console Pages Vulnerable to CSS AttacksNext Topic: UDS Accessible through Axis2 Web Administration Console


JSESSIONID Disclosed in the URL

Symptom:

The JSESSIONID was disclosed in the URL and therefore, the administrator login session was not very secure.

Solution:

To secure the administrator login session, the JSESSIONID is not disclosed in the URL.