Cannot pass cookies

JSESSIONID is definitely automatically handled as it comes from a Set-Cookie response header from the server.

Are you sure securityToken comes from a Set-Cookie response header too?