Cybersecurity team has flagged the below vulnerability in connection with SiteMinder Admin Console.
It appears that the session cookies are not being marked as secure, even though it was over https.
URL: https://example_admin_ui_host:8443/iam/siteminder/console/
Name: Session Cookie Not Marked as Secure
Severity: High
Confirmed: True
Identified Cookie(s) :
JSESSIONID
Cookie Source :
HTTP Header
Release : 12.8.05
Component : SITEMINDER WAM UI
This is out of box design with current 12.8 admin ui.
Expected result should be something like:
Set-Cookie: JSESSIONID=882D4....................695; Path=/iam/siteminder; Secure; HttpOnly
DE519825