Jump to content

aravind.potti

Members
  • Posts

    6
  • Joined

  • Last visited

 Content Type 

Forum

Downloads

Featured Visualizations

Knowledge Base

Documentation (PDF Downloads)

Blog

Documentation (Test Area)

Documentation

Dr. Jaspersoft Webinar Series

Security Advisories

Events

Profiles

Posts posted by aravind.potti

  1. Hi,

     


    I am using JRS 4.7.I have tested the JRS with IBM AppScan ,I found some security Issues :

     

    1.The application is vulnerable to  session fixation

    2. One or more session identifiers were not updated in the response.
     
     
    please let me know , how to solve these issues.
     
    Thanks & Regards,
    Aravind
     

     

  2. Hi,

     

    I am using JRS 4.7.I have tested the JRS with IBM AppScan ,I found some security Issues :

     

    1.Always use SSL and POST (body) parameters when sending sensitive information.
    2.Do not accept externally created session identifiers.
    3. Remove the cookie 'JSESSIONID' from url.
     
     
    please let me know , how to solve these issues.
     
    Thanks & Regards,
    Aravind
     
×
×
  • Create New...