My Oracle Support Banner

Insecure Cookie Attributes (Doc ID 2906121.1)

Last updated on NOVEMBER 09, 2022

Applies to:

Oracle Banking Digital Experience - Version 19.1.0.0.0 and later
Information in this document applies to any platform.

Symptoms

On : 19.1.0.0.0 version, Implementation Support

ACTUAL BEHAVIOR
---------------
Insecure Cookie Attributes

The application has implemented ‘path’ cookie attribute is set to root which may allow a malicious user to steal sensitive information like session token and launching further attack.
In cookie attributes only the path has to be set and default root should not be mentioned and path has to be defined.
 

EXPECTED BEHAVIOR
-----------------------
In cookie attributes only the path has to be set and default root should not be mentioned and path has to be defined.


BUSINESS IMPACT
-----------------------
The issue has the following business impact:
Due to this issue, a malicious user may steal sensitive information like session token and launching further attack

Changes

 No Changes done on environment.

Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Symptoms
Changes
Cause
Solution


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.