<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Resolving missing httpOnly flag dtcookie vulnerability in Troubleshooting</title>
    <link>https://community.dynatrace.com/t5/Troubleshooting/Resolving-missing-httpOnly-flag-dtcookie-vulnerability/ta-p/216936</link>
    <description>&lt;H2&gt;Self Service Summary&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;Security Team is reporting "missing httpOnly flag for dtCookie" or "Dynatrace cookies are vulnerable because httpOnly attribute is not set".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH&gt;Issue&lt;/TH&gt;
&lt;TH&gt;Solution&lt;/TH&gt;
&lt;TH&gt;Tasks&lt;/TH&gt;
&lt;TH&gt;Alternative(s)&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;httpOnly flag not set on dtCoockie&lt;/TD&gt;
&lt;TD&gt;Explain why httpOnly is not supported - see below.&lt;/TD&gt;
&lt;TD&gt;&lt;SPAN&gt;Check below information and explain it to your Security Team&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Dynatrace supports the Secure cookie attribute - see below.&lt;/P&gt;
&lt;P&gt;Submit a Support ticket if you have additional questions or concerns.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;RUM correlation requires the&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;dtCookie&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;dtPC&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;cookies to be on web requests in order to link them to user actions. However, because&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;dtCookie&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;is part of the beacon and because the RUM JavaScript sets and modifies these cookies, they don't support the&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;HttpOnly&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;flag. &lt;CODE&gt;HttpOnly&lt;/CODE&gt;&amp;nbsp;cookies are inaccessible to JavaScript, so the RUM JavaScript cannot set and modify such cookies. See&amp;nbsp;&lt;/SPAN&gt;&lt;A class="anchor" title="Learn about first-party cookie usage in Dynatrace." href="https://www.dynatrace.com/support/help/manage/data-privacy-and-security/data-privacy/cookies" target="_blank" rel="noopener"&gt;Cookies&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;for complete details.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can add the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;Secure&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;cookie attribute to all Dynatrace cookies to ensure that browsers send these cookies only over secure connections.&amp;nbsp;&lt;SPAN&gt;Before enabling the&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;Secure&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;cookie attribute, make sure that your application is completely served over secure connections. See &lt;/SPAN&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://docs.dynatrace.com/docs/manage/data-privacy-and-security/data-privacy/cookies#secure-cookies" target="_blank" rel="noopener"&gt;Secure cookies&lt;/A&gt;&lt;SPAN&gt; for more information.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Oct 2025 16:19:37 GMT</pubDate>
    <dc:creator>stefanie_pachne</dc:creator>
    <dc:date>2025-10-21T16:19:37Z</dc:date>
    <item>
      <title>Resolving missing httpOnly flag dtcookie vulnerability</title>
      <link>https://community.dynatrace.com/t5/Troubleshooting/Resolving-missing-httpOnly-flag-dtcookie-vulnerability/ta-p/216936</link>
      <description>&lt;H2&gt;Self Service Summary&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;Security Team is reporting "missing httpOnly flag for dtCookie" or "Dynatrace cookies are vulnerable because httpOnly attribute is not set".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH&gt;Issue&lt;/TH&gt;
&lt;TH&gt;Solution&lt;/TH&gt;
&lt;TH&gt;Tasks&lt;/TH&gt;
&lt;TH&gt;Alternative(s)&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;httpOnly flag not set on dtCoockie&lt;/TD&gt;
&lt;TD&gt;Explain why httpOnly is not supported - see below.&lt;/TD&gt;
&lt;TD&gt;&lt;SPAN&gt;Check below information and explain it to your Security Team&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Dynatrace supports the Secure cookie attribute - see below.&lt;/P&gt;
&lt;P&gt;Submit a Support ticket if you have additional questions or concerns.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;RUM correlation requires the&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;dtCookie&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;dtPC&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;cookies to be on web requests in order to link them to user actions. However, because&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;dtCookie&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;is part of the beacon and because the RUM JavaScript sets and modifies these cookies, they don't support the&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;HttpOnly&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;flag. &lt;CODE&gt;HttpOnly&lt;/CODE&gt;&amp;nbsp;cookies are inaccessible to JavaScript, so the RUM JavaScript cannot set and modify such cookies. See&amp;nbsp;&lt;/SPAN&gt;&lt;A class="anchor" title="Learn about first-party cookie usage in Dynatrace." href="https://www.dynatrace.com/support/help/manage/data-privacy-and-security/data-privacy/cookies" target="_blank" rel="noopener"&gt;Cookies&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;for complete details.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can add the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;Secure&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;cookie attribute to all Dynatrace cookies to ensure that browsers send these cookies only over secure connections.&amp;nbsp;&lt;SPAN&gt;Before enabling the&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;Secure&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;cookie attribute, make sure that your application is completely served over secure connections. See &lt;/SPAN&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://docs.dynatrace.com/docs/manage/data-privacy-and-security/data-privacy/cookies#secure-cookies" target="_blank" rel="noopener"&gt;Secure cookies&lt;/A&gt;&lt;SPAN&gt; for more information.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Oct 2025 16:19:37 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Troubleshooting/Resolving-missing-httpOnly-flag-dtcookie-vulnerability/ta-p/216936</guid>
      <dc:creator>stefanie_pachne</dc:creator>
      <dc:date>2025-10-21T16:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: VA scan shows missing httpOnly flag in dtcookie vulnerability</title>
      <link>https://community.dynatrace.com/t5/Troubleshooting/Resolving-missing-httpOnly-flag-dtcookie-vulnerability/tac-p/217257#M264</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/28409"&gt;@stefanie_pachne&lt;/a&gt;&amp;nbsp;do we know what JS library version this applies to?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 13:29:26 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Troubleshooting/Resolving-missing-httpOnly-flag-dtcookie-vulnerability/tac-p/217257#M264</guid>
      <dc:creator>ChadTurner</dc:creator>
      <dc:date>2023-07-07T13:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: VA scan shows missing httpOnly flag in dtcookie vulnerability</title>
      <link>https://community.dynatrace.com/t5/Troubleshooting/Resolving-missing-httpOnly-flag-dtcookie-vulnerability/tac-p/217664#M266</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/14877"&gt;@ChadTurner&lt;/a&gt;&amp;nbsp;this is a more general, typical scan result regarding Dynatracte cookies, independent of JS library versions.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 08:00:45 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Troubleshooting/Resolving-missing-httpOnly-flag-dtcookie-vulnerability/tac-p/217664#M266</guid>
      <dc:creator>stefanie_pachne</dc:creator>
      <dc:date>2023-07-12T08:00:45Z</dc:date>
    </item>
  </channel>
</rss>

