We are pleased to announce an enhancement to Oracle E-Business Suite security whereby the SameSite cookie attribute setting is now available for EBS 12.2 and EBS 12.1.3. Setting the SameSite cookie attribute provides additional protection against cross-site request forgery (CSRF). We highly recommend that you apply the required patches and enable the SameSite cookie attribute for Oracle E-Business Suite.
When enabling the SameSite cookie attribute, be certain to test integrations that are deployed to a domain that is different from the EBS domain. A few examples of integrations that may have a different domain include iProcurement punchout or single sign-on integration with Oracle Access Manager or Identity Cloud Service.
For Oracle E-Business Suite Release 12.2, Patch 29672027:R12.TXK.C delivers context file parameters to enable and configure the SameSite cookie attribute. For the latest requirement and configuration details, refer to the following:
- Using Certified HTTP Security Headers in the Oracle E-Business Suite Security Guide Release 12.2
For Oracle E-Business Suite Release 12.1.3, Patch 30185574:R12.FND.B delivers a profile to enable and configure the SameSite cookie attribute. For the latest requirement and configuration details, refer to the following:
- Use the SameSite Cookie Attribute in the Secure Configuration Guide for Oracle E-Business Suite Release 12.1, as found in Secure Configuration for Oracle E-Business Suite Release 12.1 (MOS Note 403537.1)
- FAQ: Oracle E-Business Suite Security (MOS Note 2063486.1)
- Identifying the Latest Critical Patch Update for Oracle E-Business Suite Release 12 (MOS Note 248400.1)
- Oracle E-Business Suite Security Guide Release 12.2 – Secure Configuration
- Secure Configuration for Oracle E-Business Suite Release 12.1 (MOS Note 403537.1)
Related Articles
- Updated: Oracle E-Business Suite Security FAQ
- EBS Security Feature Allowed Redirects Now Available for EBS 12.1.3
- EBS Security Feature Allowed Resources Now Available for EBS 12.1.3
- Updated: Secure Oracle E-Business Suite with Allowed Resources
- HTTPOnly Cookie Flag Now Available for EBS 12.2
- HTTPOnly Cookie Flag Now Available for EBS 12.1.3
- Critical Patch Update for April 2020 Now Available
