If this is true, it's a stupid mistake on the security team's part. A ridiculous flaw.
The minimum they should do is bind the session on IP and invalidate it if a different IP tries to access the service with it.

Also, I believe their sessions last 1 month... just checked this site's session id... heh.