IBM Support

How to set HttpOnly Flag for JSESSIONID_ibm_console_16310 cookie on WebGUI

Question & Answer


Question

Security scan flagged out that the JSESSIONID_ibm_console_16310 cookie does not have the HttpOnly flag attached to it and is exposed to security vunerability.

[{"Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSSHTQ","label":"Tivoli Netcool\/OMNIbus"},"ARM Category":[{"code":"a8m500000008bTXAAY","label":"WebGUI-\u003EDASH-\u003EDASH UI Services - Security Category"}],"ARM Case Number":"","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"All Version(s)"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Product Synonym

httponlyflag, jsession,webgui

Document Information

Modified date:
09 May 2025

UID

ibm16261823