SAP Knowledge Base Article - Preview

2068872 - HttpOnly and Secure cookie attributes


  • There are cookies set by the Netweaver Application server that do not have 'Secure' and/or 'HttpOnly' attributes. This may have been highlighted during a vulnerability scan for example.
  • You would like to ensure that these cookies are set with 'Secure' and 'HttpOnly' attributes.



SAP Netweaver Application Server


SAP NetWeaver 7.0 ; SAP NetWeaver 7.3 ; SAP NetWeaver 7.4 ; SAP NetWeaver 7.5 ; SAP enhancement package 1 for SAP NetWeaver 7.0 ; SAP enhancement package 1 for SAP NetWeaver 7.3 ; SAP enhancement package 2 for SAP NetWeaver 7.0 ; SAP enhancement package 3 for SAP NetWeaver 7.0


icf/set_HTTPonly_flag_on_cookies, SystemCookiesDataProtection, SystemCookiesHTTPSProtection, ume.logon.httponlycookie,, login/ticket_only_by_https,, Missing Secure Attribute in Encrypted Session (SSL) Cookie , KBA , BC-JAS-WEB , Web Container, HTTP, JavaMail, Servlets , BC-MID-ICF , Internet Communication Framework , EP-PIN-AI , Application Integration , CA-FLP-ABA , SAP Fiori Launchpad ABAP Services , MOB-UIA-LIB-AUT , Authentication , BC-JAS-SEC-LGN , Logon, SSO , How To

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.