Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
LeeBingKang
Advisor

"Session cookie has no SameSite attribute: Session" vulnerability found on Management server R80.40

Recently, my client ran a VA scan on their R80.40 managment server and found out that is a vulnerability called "Session cookie has no SameSite attribute: Session". I tried to find from internet resources and CheckPoint SK, but no relevant resolution for this issue.

Hence, appreciate if you all can share some suggestions on solving this matter.

 

Thank you.

0 Kudos
3 Replies
Chris_Atkinson
Employee Employee
Employee

Is the machine running a recent jumbo?

Regardless I would suggest engaging TAC with relevant details. 

CCSM R77/R80/ELITE
0 Kudos
LeeBingKang
Advisor

Hi @Chris_Atkinson , the machine is not with latest Jumbo Hotfix, but i will install the latest recommended hotfix as it resolved the Slowloris DoS vulnerability.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

T180 and higher will help with Slowloris

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events