11
I'm looking for a plain English, "for dummies" explanation of how does JSESSIONID work from security aspects
- Can someone who merely knows my current JSESSIONID impersonate / hijack my session?
- In what scenarios JSESSIONID will be part of the URL, and is this OWASP #2 security risk (scenario #1) still relevant for latest versions of Tomcat / Glassfish, and if so, what to "turn off/on" to prevent it?