There Is No Sessions Time Out For Inactive Users

< 1 min read

Impact Area

Security

Severity

Medium

Affected Element

Org Config

Rule ID #

SF-0167

Impact #

Increased vulnerability to session hijack attacks.

Remediation #

Set a timeout value. From Setup, enter “Session Settings” in the Quick Find box, then select Session Settings. Then enable “Timeout Value”.

Time to fix #

30 min

References #

This rule is linked to Common Weakness Enumeration CWE-613 Insufficient Session Expiration.

Updated on March 21, 2025
Was it helpful ?