Technology Stack - EBS (MOSC)

MOSC Banner

Disable OADevmode cookie

edited Nov 19, 2012 10:36AM in Technology Stack - EBS (MOSC) 1 commentAnswered
We just had a penetration test on R12 EBS and they found that our system is setting OADevmode cookie. How to disable that? Please find more information below -

• Oracle applications support a developer mode that allows any use to view limited error or debugging messages.
• The developer mode is enabled by setting the "OADevmode" cookie to 1.
• The messages sent to the user may reveal information that helps an attacker to craft exploits better suited to the
environment.

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center