users@glassfish.java.net

Re: HTTP Session crossing between users (for the lack of a ...

From: <forums_at_java.net>
Date: Wed, 13 Apr 2011 09:55:26 -0500 (CDT)

If cookies are disabled and a jsessionid matrix parameter is set, then it
would be possible to bookmark someone else's session. This is true of any
Java servlet container, as far as I know. Best, Laird

--
[Message sent by forum member 'ljnelson']
View Post: http://forums.java.net/node/791266