Which is the Valid Scenario of Broken Authentication and Session Management.
User able to access the page which he/she is not Authorised.
Exposing Authentication/Session details as part of URL
Sending Financial Data request as part of the request URL.
None of the Above