Well-Architected
OWASP Top 10
Start Free
Use of Session IDs in Visualforce
Share
Overview
Session IDs should be treated as secrets and handled with care, as they may allow access to the Salesforce API on behalf of the running user.
Business Impact
Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.
Is your Salesforce solution affected by Use of Session IDs in Visualforce?
Clayton detects anti-patterns and offers automated fix advice to kickstart your Well-Architected journey.
Scan your solution
Resources
$Api
Identification and Authentication Failures
Reliance on Untrusted Inputs in a Security Decision
Common
Incidence
How common is this issue?
10%
1%
8%
lower
Exposure
How long do organizations remain exposed before fixing the problem?
4 years
3 months
94%
shorter
Benchmark
With Clayton
Frameworks
Trusted
Secure
Session Security
Session Management
A07:2021 – Identification and Authentication Failures
Found a mistake?
If you think something is incorrect, missing or misleading please let us know.
Report an error