Identity Management (MOSC)

MOSC Banner

OAM Sessionid strength

edited May 25, 2016 5:04AM in Identity Management (MOSC) 1 commentAnswered

I'm dealing with a Security scan where it found a vulnerability in the session token strengh. Due to a low entropy, I need to increase the length of the session id tokens in OAM. Does anybody have experience with it?

References to this vulnerability are listed below:

High – Session Strength

CWE-330: http://cwe.mitre.org/data/definitions/330.html 

OWASP2013-A2: http://www.owasp.org/index.php/Top_10_2013-A2 

Thanks in advance,

-Stephane

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center