Vulnerability Scan - Missing Secure Attribute in Encrypted Session (SSL) Cookie
search cancel

Vulnerability Scan - Missing Secure Attribute in Encrypted Session (SSL) Cookie

book

Article ID: 247492

calendar_today

Updated On:

Products

Clarity PPM On Premise

Issue/Introduction

Upon running the Vulnerability Scan in Clarity we are receiving the following vulnerability: - 

"Missing Secure Attribute in Encrypted Session (SSL) Cookie"

Resolution

a) Log into CSA/NSA

b) Click on the Server

c) Click on the Application Tab

d) There is an option for "Use Secure Session Cookie"

e) Enable the above option

Note: On a same page Under Application Instance: NSA There is an option for "Use Secure Session Cookie"

f) Enable that option also 

g) Restart the Clarity Services

h) Run the Vulnerability Scan

You can perform the above steps in lower environment and then proceed to Prod.