OAM Sessionid strength
I'm dealing with a Security scan where it found a vulnerability in the session token strengh. Due to a low entropy, I need to increase the length of the session id tokens in OAM. Does anybody have experience with it?
References to this vulnerability are listed below:
High – Session Strength
CWE-330: http://cwe.mitre.org/data/definitions/330.html
OWASP2013-A2: http://www.owasp.org/index.php/Top_10_2013-A2
Thanks in advance,
-Stephane