SAP Knowledge Base Article - Preview

2706131 - AS Java Security Vulnerability - SSL Cookie without Secure and HttpOnly flags

Symptom

An external security vulnerability check tool reports vulnerability:

"SSL Cookie without Secure and HttpOnly flags"


Read more...

Environment

AS Java all versions

Product

SAP NetWeaver Application Server for Java all versions ; SAP NetWeaver all versions

Keywords

Secure cookie, SSL Cookie, HttpOnly flags, Security vulnerability , KBA , BC-JAS-WEB , Web Container, HTTP, JavaMail, Servlets , BC-JAS-SEC , Security, User Management , BC-MID-ICF , Internet Communication Framework , EP-PIN-AI , Application Integration , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.