Use of Session IDs in Visualforce

Overview

Session IDs should be treated as secrets and handled with care, as they may allow access to the Salesforce API on behalf of the running user.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Common

Incidence

How common is this issue?
10%1%
arrow down8%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
4 years3 months
arrow down94%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconSession SecurityiconSession ManagementiconA07:2021 – Identification and Authentication Failuresicon