My application is deployed on Websphere 8.5. and there is a vulnerability reported for jsessionid not changing post login. we tried all possible approaches to change the jsessionid post successful login but it's not working.
Hence we are trying to hinder the session id from the browser so it is not visible. is there any way to achieve this in WebSphere 8.5
the authentication is happening via SiteMinder sso