Disable OADevmode cookie
We just had a penetration test on R12 EBS
and they found that our system is setting OADevmode cookie. How to
disable that? Please find more information below -
• Oracle applications support a developer mode that allows any use to view limited error or debugging messages.
• The developer mode is enabled by setting the "OADevmode" cookie to 1.
• The messages sent to the user may reveal information that helps an attacker to craft exploits better suited to the
environment.
• Oracle applications support a developer mode that allows any use to view limited error or debugging messages.
• The developer mode is enabled by setting the "OADevmode" cookie to 1.
• The messages sent to the user may reveal information that helps an attacker to craft exploits better suited to the
environment.
Tagged:
0