Is session guessing attacks or accidental session collision a concern on EAP 6?
Issue
- Is session guessing attacks or accidental session collision a concern on EAP 6?
- Let's say user1 logs in and then their session times out, but he leaves his browser open. Then user2 logs in after this and gets a sessionid; could user2 get user1's old sessionid? And then if user1 becomes active again, could he see user2's session data?
- Or could a malicious user easily guess a valid in use session id?
Environment
- JBoss Enterprise Application Platform (EAP) 6.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.