Using the My Oracle Support Portal (MOSC)

MOSC Banner

Oracle EBS security

edited Mar 5, 2018 4:03AM in Using the My Oracle Support Portal (MOSC) 2 commentsAnswered

HI

Application : 12.1.3

Database : 12.1.0.2.0

1 # Currently we have a security issues EBS iRecruitment external portal ....How do we apply a secure and HttpOnly attributte to the web cookies, is it config changes to the middle Tier.

Cookies downloaded from the Vacancies web portal are not securely configured which may lead to unauthorized access.

2 # The HTTP headers are not adequately configured which may expose users to phishing attacks.

On the application config we need to include the following in the respone header: in which config file do we add the below missing headers 

X-Frame-Options

X-Content-Type-Options

X-XSS-Protection

3 # The Vacancies web portal does not enforce the use of secure connections, which may allow an attacker to eavesdrop the traffic to obtain unauthorized access or tamper with information being transmitted.

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center