Session Fixation in EAP 6.4.9

Posted on
  1. Need to know how to prevent a Session Fixation attack in EAP 6.4.9

  2. The jsession id doesn't change after the login,

  3. Tried the below solutions but it doesn't work,
    https://bugzilla.redhat.com/show_bug.cgi?id=1189465
    https://access.redhat.com/solutions/227923

Responses