SAP Knowledge Base Article - Preview

3749176 - Session Cookie Does Not Contain the "Secure" Attribute

Symptom

  • Vulnerability identified: "Session Cookie Does Not Contain the 'Secure' Attribute."
  • HTTP cookie missing Secure attribute on port 8081.
  • Cookies are set without the 'Secure' attribute, potentially exposing session data during unencrypted HTTP requests.
  • Issue is related to use of port 8081 for Wily.


Read more...

Environment

  • Product: SAP Extended Diagnostics by CA Wily
  • Introscope by CA Technologies

Product

SAP Extended Diagnostics by CA Wily all versions

Keywords

session cookie, secure attribute, missing secure, http cookie, port 8081, introscope, enterprise manager, wily, em-jetty-config.xml, jetty, secure flag, https, vulnerability, cookie security. , KBA , XX-PART-WILY , Introscope by CA Technologies , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.