How do I prevent a Session Fixation attack in JBoss EAP 6
Issue
- I need to know how to prevent a Session Fixation attack.
- Our security team has recently identified a potential security risk in the management of JSESSIONIDs via j_security_check in JBoss EAP 6. The issue is described well enough in this existing JBoss 7 issue here below. Will this be fixed for EAP 6?
- https://issues.jboss.org/browse/AS7-5315
- How can we generate a new session id after login?
Environment
- JBoss Enterprise Application Platform (EAP)
- 6.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.