Skip to Content
0

Portal JSESSIONID URL need to hide in browser..?

Jan 09, 2017 at 06:20 AM

67

avatar image

Dear All,

Please suggest me the how to hide the JSESSIONID URL in portal.I did some configuration in my server end but it should not display in the browser.

This configuration done.

https://blogs.sap.com/2012/05/10/implementing-secure-session-management-for-sap-netweaver-java-web-application-solutions/

and

com.sap.portal.appintegrator-->Common_Configuration-->Add_Jsessionid_To_URL -->set to false.

But no use .Please any other configuration is required...?.I am facing the security issues for my inter team.

Issues : This application passes the session id in the URL after login into application. An adversary can steal the session id by sniffing or from logs and hijack the user session to perform malicious activities.

10 |10000 characters needed characters left characters exceeded
* Please Login or Register to Answer, Follow or Comment.

0 Answers