V-274600
Application Programming Interface (API) Security Requirements Guide
Title
The API must protect Session IDs via encryption.
Description
<VulnDiscussion>Encrypting Session IDs protects them from interception and unauthorized access, preventing session hijacking and ensuring the confidentiality and integrity of user sessions.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Re...
Fix Text (Documentation Requirement)
Build or configure the API to protect session IDs from interception or from manipulation.