Skip to Content
avatar image
Former Member

Portal JSESSIONID URL need to hide in browser..?

Dear All,

Please suggest me the how to hide the JSESSIONID URL in portal.I did some configuration in my server end but it should not display in the browser.

This configuration done.

https://blogs.sap.com/2012/05/10/implementing-secure-session-management-for-sap-netweaver-java-web-application-solutions/

and

com.sap.portal.appintegrator-->Common_Configuration-->Add_Jsessionid_To_URL -->set to false.

But no use .Please any other configuration is required...?.I am facing the security issues for my inter team.

Issues : This application passes the session id in the URL after login into application. An adversary can steal the session id by sniffing or from logs and hijack the user session to perform malicious activities.

Add comment
10|10000 characters needed characters exceeded

  • Get RSS Feed

0 Answers