Best Practice 5_Security_TM: Proactively Invalidate Inactive Sessions
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2 hours ago
By Default , glide.active.session.timeout.invalidate.session property is set to false
When glide.active.session.timeout.invalidate.session is not set to true, there can be a small interval of time where a timed out session is not invalidated (60 or more seconds depending on queue size).
If a session is hijacked, an attacker may be able to use a session during this small period of time.
Servicenow Recommendation:
Recommendation of ServiceNow is to set glide.active.session.timeout.invalidate.session property value to true.
#Article #Security #Best Practice
0 REPLIES 0
