Products | Versions |
---|---|
Spotfire Statistica | 12.7 and higher |
For any IIS website installed with Statistica Server, like Web Data Entry, use of the URI, which contains a session string, can be copied from one user to another. The user whom obtains the new URL that contains the same session screen can impersonate the first user. This is a security risk. How can this be resolved?
1. Open IIS Manager, go to Sites | Default Web Site | DataEntry, double-click Sessions:
2. Select "Use Cookies" under Mode in Cookie Settings section:
3. Click "Apply" to the right.