During QUALYS Web Application Scanning of user system like Oracle Fusion (Integration layer), if one is facing the below security vulnerability, then follow the steps mentioned in the solution.
ID and Name
150123 and Cookie Does Not Contain The “HTTPOnly” Attribute
Threat
The cookie does not contain the “HTTPOnly” attribute.
Impact
Cookies without the “HTTPOnly” attribute are permitted to be accessed via JavaScript. Cross-site scripting attacks can steal cookies which could lead to user impersonation or compromise of the application account.
Solution
- Go to below location of Oracle Fusion server: /<Env_Name>/products/middleware/<Server_Name>/server/lib/consoleapp/webapp/WEB-INF
- Edit File Name: weblogic.xml
- Add tag within existing “<session-descriptor>”: <http-only>true</http-only>
NOTE: Please restart Admin and all the other SOA and OSB managed servers, post the above changes.

Amazing stuff!
LikeLike
Great content!
LikeLike
Keep posting on security please…..
LikeLike
Good security blog!
LikeLike
Security and its vulnerability are important to my project…Thanks for sharing!
LikeLike
solved my security vulnerability issue…
LikeLike
Keep sharing such blogs!
LikeLike
Promising content
LikeLiked by 1 person
Good post and keep sharing this knowledge!
LikeLike
cleared my concepts of security vulnerabiltity
LikeLike
So clearly explained – 👍
LikeLiked by 2 people
Good content!! Helpful…
LikeLike
Neatly explained…. Good job
LikeLike
Great job
LikeLike
Nice content
LikeLike
Good content, was able to reuse in my Project
LikeLike
Good job
LikeLiked by 1 person
Keep posting
LikeLike
Good content
LikeLike
Brilliant work thank you
LikeLike
Keep blogging! Very helpful
LikeLike
Very helpful!!
LikeLike
Very helpful, thank you
LikeLike
Good content
LikeLike
Good helpful
LikeLike
Brilliant
LikeLike
Great content!
LikeLike
Helped my technical issues
LikeLike
Great job.
LikeLike
Good work!!
LikeLike
Nicely articulated!!!
LikeLiked by 1 person
Keep your posts coming, it’s always a pleasure to read how you overcome the day to day issues and more
LikeLike