• Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
    Dedicated community for Japanese speakers
  • 한국 커뮤니티
    Dedicated community for Korean speakers
Exit
0

J2EE Misconfiguration: Insufficient Session ID Length

New Here ,
May 15, 2017 May 15, 2017

Copy link to clipboard

Copied

Hey Guys,

We just had a PCI scan on one of our servers, and the following issue was returned:

J2EE Misconfiguration: Insufficient Session ID Length

My understanding is that the Session ID length is set in the underlying JVM for CF.

Is there any solution to this?

Thanks

Steve

Views

273

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
May 16, 2017 May 16, 2017

Copy link to clipboard

Copied

Check CFAdmin Memory Variables

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
May 16, 2017 May 16, 2017

Copy link to clipboard

Copied

LATEST

Sorry ... by length i DON'T mean the length of the timeout.

By length, I mean the length of the string identifying a particular session.


So, they're currently of the form 1B28985AA915BCAE8B53537A1B5B6020.cfusion, but the scan failed because it's saying that that string isn't long enough, and could technically be guessed to hijack the session.

Thanks


Steve

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Resources
Documentation