Troubleshooting
Problem
Customer has used a security tool to check for vulnerabilities in the Cognos Controller architecture. This security tool's report has warned the customer that there are 'Missing Secure Attribute in Encrypted Session (SSL) Cookie' vulnerabilites on the Controller application server. How can the customer solve this?
Symptom
Security reporting tool warns about Missing Secure Attribute in Encrypted Session (SSL) Cookie.
- It may say: "The web application sends non-secure cookies over SSL"
- It may suggest the following: "It may be possible to steal user and session information (cookies) that was sent during an encrypted session".
[{"Product":{"code":"SS9S6B","label":"IBM Cognos Controller"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Component":"Controller","Platform":[{"code":"PF033","label":"Windows"}],"Version":"10.2.1","Edition":"","Line of Business":{"code":"LOB76","label":"Data Platform"}},{"Product":{"code":"SSMRTZ","label":"IBM Cognos Controller on Cloud"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Component":" ","Platform":[{"code":"","label":""}],"Version":"","Edition":"","Line of Business":{"code":"LOB76","label":"Data Platform"}}]
Log InLog in to view more of this document
This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.
Was this topic helpful?
Document Information
Modified date:
08 May 2025
UID
swg21963787