Exit
  • Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
  • 한국 커뮤니티
0

J2EE Misconfiguration: Insufficient Session ID Length

New Here ,
May 15, 2017 May 15, 2017

Hey Guys,

We just had a PCI scan on one of our servers, and the following issue was returned:

J2EE Misconfiguration: Insufficient Session ID Length

My understanding is that the Session ID length is set in the underlying JVM for CF.

Is there any solution to this?

Thanks

Steve

436
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
May 16, 2017 May 16, 2017

Check CFAdmin Memory Variables

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
May 16, 2017 May 16, 2017
LATEST

Sorry ... by length i DON'T mean the length of the timeout.

By length, I mean the length of the string identifying a particular session.


So, they're currently of the form 1B28985AA915BCAE8B53537A1B5B6020.cfusion, but the scan failed because it's saying that that string isn't long enough, and could technically be guessed to hijack the session.

Thanks


Steve

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Resources