SESSION MANAGEMENT (SM3)

Ryan can use a single account in parallel since concurrent sessions are allowed

SESSION MANAGEMENT
3

Ryan can use a single account in parallel since concurrent sessions are allowed

OWASP SCP

68

OWASP ASVS

3.3.3,3.3.4

OWASP AppSensor

CAPEC

-

SAFECODE

28

How to play?

In some ecommerce applications it may be desirable to allow customers to be logged in using multiple browsers/devices. However that would be unusual for administrative users, or users of more sensitive data. Even if concurrent sessions are allowed. consider what should occur in other sessions when a user changes their password, or changes their delivery address, or logs out, or times out, or authentication failure occurs.

NB: This card relates to concurrent sessions created by authenticating more than once in different browsers/devices. See SM 6 for using the same session identifier in concurrent sessions.

Mappings

OWASP ASVS (4.0): 3.3.3 ,3.3.4

Capec:

OWASP SCP: 68

OWASP Appsensor:

Safecode: 28

ASVS (4.0) Cheatsheetseries Index

ASVS V3.3 - Session Logout and Timeout Requirements

No suitable mappings were found.

Attacks

Cross-Site Scripting (XSS)

Password Guessing/Brute Force Attacks

Session Fixation

Session Hijacking (Man-in-the-Middle)

Session Timeout Issues

OWASP Cornucopia

  • OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, platform and technology-agnostic, and is free to use.
  • OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar licence to this one.
  • © 2012-2025 OWASP Foundation. The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.