SV-54395r3_rule
V-41818
SRG-APP-000223-WSR-000145
SRG-APP-000223-WSR-000145
CAT II
10
Configure the web server to only accept session IDs that are created by the web server.
Review the web server documentation and deployed configuration to determine whether the web server accepts session IDs that are not system-generated.
If the web server does accept non-system-generated session IDs, this is a finding.
V-41818
False
SRG-APP-000223-WSR-000145
Review the web server documentation and deployed configuration to determine whether the web server accepts session IDs that are not system-generated.
If the web server does accept non-system-generated session IDs, this is a finding.
M
2557