Forum Discussion

SSHSSH_97332's avatar
SSHSSH_97332
Icon for Nimbostratus rankNimbostratus
Nov 22, 2013

Application Simultanoues session logon

Which ASM violation check protects against this vulnerability "Application Simultanoues session logon" ? description for this vulnerability is below :

 

If application allow simultaneous logons for the same user, from same client IP address. User Session on a particular system will not terminate if any one of the session/browser is open.

 

A malicious user who has physical access to the system could gain access to an already active session and perform actions as a legitimate user.