One of the major drawbacks of J2EE session variables in ColdFusion is that changes like their “safe” cookies are widespread.
This means that every site running on this instance must run under https, including the ColdFusion administrator. For servers hosting multiple sites that require sessions, this will usually be problematic. In addition, if you are using ColdFusion Administrator from the embedded web server, there is little process to get it working under ssl.
If you need the documented benefits of J2EE cookies and you want the cookie to be secure, all sites requiring sessions must be on https.
If you do not need any documented benefits of J2EE cookies and you are using CF9 or later, you are better off with ColdFusion cookies.
Please note that Railo still has the same problem, but with more flexibility, because the cfapplication tag has a sessiontype attribute, where you can choose between j2ee or cf session cookies for each site.
source share