Skip to content
October 1, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • Technique
  • Session mechanism in the details
  • Technique

Session mechanism in the details

Do Son December 28, 2017 5 minutes read
Session mechanism

Session mechanism

In addition to using cookies, Web applications often use Session to record client status. A session is a mechanism used by the server to record the status of the client. It is simpler to use than the cookie, which in turn increases the storage pressure on the server.

Image: owasp

What is Session?

A session is another mechanism to record the status of the client, the difference is that the cookie is stored in the client browser, and the session is saved on the server. When the client browser accesses the server, the server records the client information in some form on the server. This is Session. When the client browser visits again, it only needs to find the status of the client from the Session.

If the cookie mechanism is to determine the identity of the client by checking the “pass” on the client, then the Session mechanism is to confirm the identity of the client by checking the “client list” on the server. Session equivalent to the program created on the server a customer file, customer visit only need to check the customer file table on it.

To achieve user login

The corresponding Session class javax.servlet.http.HttpSession category. Each visitor corresponds to a Session object, all of the client’s state information is stored in this Session object. The Session object is created when the client requests the server for the first time. A session is also a key-value property pair that reads and writes customer state information using the getAttribute(Stringkey) and setAttribute(String key, Objectvalue) methods. Servlet through the request.getSession() method to obtain the client’s Session.

Pay attention to the Session Session directly saved Person object and Date class object, to use than Cookie convenient.

When multiple clients execute a program, the server saves multiple client sessions. Get Session also do not need to declare the access to the Session. Session mechanism determines that the current client will only get their own Session, and will not get someone’s Session. The client’s sessions are also independent of each other, not visible to each other.

Tip: Session is easier to use than Cookie, but too many sessions stored in the server’s memory can put pressure on the server.

Session lifecycle

Session saved on the server. In order to obtain higher access speed, the server generally Session in memory. Each user will have a separate session. If the Session content is too complicated, memory overflow may occur when a large number of clients access the server. Therefore, the information in the Session should be as concise as possible.

A session is created automatically when the user first accesses the server. Need to pay attention to only visit JSP, Servlet and other procedures will create a Session, visit only static resources such as HTML, IMAGE and will not create a Session. If you have not generated a Session, you can also use request.getSession (true) to force the session to be generated.

After the Session is generated, as long as the user continues to access the server, the server updates the last access time of the Session and maintains the session. Each time a user accesses the server, regardless of whether the session is read or written, the server considers the user’s session “active” once.

Session is valid

Because there will be more and more users to access the server, so Session will be more and more. To prevent memory overflow, the server will not an active session for a long time from the memory to delete. This is the Session’s timeout. If more than the timeout did not visit the server, the Session will automatically expire.

The timeout of the session is the maxInactiveInterval property, which can be obtained through the corresponding getMaxInactiveInterval() and modified by setMaxInactiveInterval(longinterval).

Session timeout can also be modified in web.xml. In addition, Session can be invalidated by calling Session’s invalidate () method.

Session on the browser requirements

Although the Session is stored on the server and is transparent to the client, its normal operation still requires client-side browser support. This is because Session requires the use of cookies as an identifier. The HTTP protocol is stateless. The Session cannot determine whether it is the same client based on the HTTP connection. Therefore, the server sends a cookie named JSESSIONID to the client browser whose value is the Session id (ie, HttpSession.getId() the return value). Session based on the cookie to identify whether the same user.

The cookie is automatically generated by the server, its maxAge property is generally -1, which means that only the current browser is valid, and the browser window is not shared, close the browser will lapse.

Therefore, when two browser windows of the same machine access the server, two different sessions are generated. Except for new windows opened by links, scripts, etc. in the browser window (ie, not double-click on an open window such as a desktop browser icon). Such sub-window will share the parent window’s Cookie, it will share a Session.

Note: The new browser window will generate a new Session, except the child window. Child window will share the parent window Session. For example, right-clicking on a link and selecting “Open in a new window” in the pop-up shortcut menu will allow the child window to access the parent’s Session.

What if the client browser disables cookies or does not support cookies? For example, most mobile browsers do not support cookies. Java Web Another solution provided: URL address rewriting.

URL address rewriting

URL address rewriting is a solution that does not support cookies for clients. The principle of URL address rewriting is to rewrite the id information of the user Session to the URL address. The server can parse the rewritten URL for the Session’s id. This allows you to use the Session to record user status even though the client does not support cookies.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Tags: Session mechanism

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2025-41753CVSS 9.3
    The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient...
    📅 Updated: Oct 1, 2026
  • CVE-2026-92966CVSS 9.1
    The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable...
    📅 Updated: Oct 1, 2026
  • CVE-2026-82824CVSS 9.3
    Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access,...
    📅 Updated: Oct 1, 2026
  • CVE-2026-82825CVSS 9.3
    Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated...
    📅 Updated: Oct 1, 2026
  • CVE-2026-82827CVSS 9.3
    Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT...
    📅 Updated: Oct 1, 2026
  • CVE-2026-82829CVSS 9.3
    Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain...
    📅 Updated: Oct 1, 2026
  • CVE-2026-76142CVSS 9.3
    Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows...
    📅 Updated: Oct 1, 2026
  • CVE-2026-102425CVSS 9.5
    Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa...
    📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.