AppScan cannot scan the web system with CAPTCHA on the landing page.
After recording and logging in, in the scan configuration settings, set the session ID in the parameters saved under login management, and cancel the tracking for JSESSIONID. In this way, there will be no session timeout if you scan again.