BNavin118206 (Community Member) asked a question.

Insufficient Session Expiration

The lack of proper session expiration may improve the likely success of certain attacks. For example, an attacker may intercept a session ID, possibly via a network sniffer or Cross-site Scripting attack. Although short session expiration times do not help if a stolen token is immediately used, they will protect against ongoing replaying of the session ID. In another scenario, a user might access a web site from a shared computer (such as at a library, Internet cafe, or open work environment). Insufficient Session Expiration could allow an attacker to use the browser's back button to access web pages previously accessed by the victim.

 

i used session timeout in web.xml already ,but getting issue again.please let me know


Topics (10)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.