By
"Is the only way to get the session of super user is through username/password information of super user?"
I meant that when I have username/password I can definately get the Session Manager and appropriate session using getSessionManager() and getSession() APIs. But what if I don't know the username/password but still need to use super user's session from within an aspect's code?
You could create a user in the repository with an inline password (no need for this user to be on the domain). Then you can use this user's info
My 2 cents