Session Fixation in Java

Overview of Session Fixation
A detailed overview on session fixation can be found here: Session Fixation

Countermeasures
(Comment: Could expand on why this is important) session.invalidate; session=request.getSession(true);
 * Session ID should be regenerated after login, and switching in and out of SSL


 * Disable URL rewriting

(Comment: How does one do this in the popular web containers?, and what threat does this mitigate?)