Need to Resolve HTTP Cookie ‘Secure’ Property Transport Mismatch in Oracle EBS R12.2.10
Hello Oracle Experts,
We are currently facing an audit finding related to HTTP Cookie ‘Secure’ Property Transport Mismatch in our Oracle E-Business Suite R12.2.10 environment running on Oracle Linux 7.9.
Audit Description :
The remote web server sends out cookies to clients with a 'secure'
property that does not match the transport, HTTP or HTTPS, over which
they were received. This may occur in two forms :
- The cookie is sent over HTTP, but has the 'secure'
property set, indicating that it should only be sent
over a secure, encrypted transport such as HTTPS.
This should not happen. - The cookie is sent over HTTPS, but has no 'secure'