We are pleased to announce an enhancement to Oracle E-Business Suite security whereby the HTTPOnly cookie flag is set automatically for the EBS session cookie (sometimes also called ICX session cookie) when the requirements listed below are met.  Setting the HTTPOnly cookie flag provides additional security by concealing the cookie from client-side scripts. 

Requirements

This feature is automatically available to all EBS 12.2.x customers who have met the following requirements:

References

Related Articles