We are pleased to announce an enhancement to Oracle E-Business Suite security whereby the HTTPOnly cookie flag is set automatically for the EBS session cookie (sometimes also called ICX session cookie) when the requirements listed below are met. Setting the HTTPOnly cookie flag provides additional security by concealing the cookie from client-side scripts.
Requirements
This feature is automatically available to all EBS 12.2.x customers who have met the following requirements:
- Applied R12.ATG_PF.C.DELTA.7 (24690680)

- Migrated to Java Web Start by following Using Java Web Start with Oracle E-Business Suite (MOS Note 2188898.1)
References
- FAQ: Oracle E-Business Suite Security (MOS Note 2063486.1)
- Using Java Web Start with Oracle E-Business Suite (MOS Note 2188898.1
- Identifying the Latest Critical Patch Update for Oracle E-Business Suite Release 12 (MOS Note 248400.1)
