What do you expect me to comment on this? The change is the same change that i've commited 6 days ago to the code repository of OpenACS [1] noted in the posting nr 6 in this thread [2], posted 5 minutes before the posting of Klaus.
The question is rather, AppScan should stop complaining about using the same session id after the privilege change
-gn