/build/static/layout/Breadcrumb_cap_w.png

Kace Server - MIssing HttpOnly Attribute in Session Cookie"

Anyone else come across this? Security ran a scan and the K1000 and K2000 both have this vulnerabilty.

ISSUE: "Missing HttpOnly Atribute in Session Cookie"

There was some question here at my orginization about whether the 5.5 upgrade addressed it, but I didn't see any reference in the release notes or elsewhere so I don't think it was addressed.

The "Fix recommendation" is to "Add the 'HttpOnly' attribute to all session cookies. This sounds like something Kace support would have to do, but if it's a big deal and isn't already done, then I would expect it's not done for a reason.

Any info at all on this odd ball would be great.

 

Thanks,


3 Comments   [ + ] Show comments
  • What are you using for a Security scan? - KACE_Mary 10 years ago
  • Hi Mary, Thanks for replying.

    Scan tool==> IBM AppScan - We're a tiered setup and a different group runs the scan. We have plenty of other internal and external sites, but as far as I know, only our K1000 and K2000 came up with it. - murbot 10 years ago
  • I have asked a few engineers and they have not seen this. Can you open a ticket with KACE technical support and provide the scan information. Ask for the ticket to be assigned to Mary. - KACE_Mary 10 years ago

Answers (0)

Be the first to answer this question

Don't be a Stranger!

Sign up today to participate, stay informed, earn points and establish a reputation for yourself!

Sign up! or login

Share

 
This website uses cookies. By continuing to use this site and/or clicking the "Accept" button you are providing consent Quest Software and its affiliates do NOT sell the Personal Data you provide to us either when you register on our websites or when you do business with us. For more information about our Privacy Policy and our data protection efforts, please visit GDPR-HQ