Insecure Cookie Attributes
(Doc ID 2906121.1)
Last updated on NOVEMBER 09, 2022
Applies to:
Oracle Banking Digital Experience - Version 19.1.0.0.0 and laterInformation in this document applies to any platform.
Symptoms
On : 19.1.0.0.0 version, Implementation Support
ACTUAL BEHAVIOR
---------------
Insecure Cookie Attributes
The application has implemented ‘path’ cookie attribute is set to root which may allow a malicious user to steal sensitive information like session token and launching further attack.
In cookie attributes only the path has to be set and default root should not be mentioned and path has to be defined.
EXPECTED BEHAVIOR
-----------------------
In cookie attributes only the path has to be set and default root should not be mentioned and path has to be defined.
BUSINESS IMPACT
-----------------------
The issue has the following business impact:
Due to this issue, a malicious user may steal sensitive information like session token and launching further attack
Changes
No Changes done on environment.
Cause
To view full details, sign in with your My Oracle Support account. |
|
Don't have a My Oracle Support account? Click to get started! |
In this Document
Symptoms |
Changes |
Cause |
Solution |