Introduction Vulnerability or penetration tests may flag DX Experience Analytics (AXA) Browser Agent cookies as unsecure because they lack HttpOnly and Secure attributes. This occurs when the Browser Agent is configured to use cookies for session tracking or response decoration.
Symptoms Security scanners report the following cookies as a vulnerability:
x-apm-ba-BAFinPrtx-apm-brtm-bt-pvx-apm-brtm-bt-pBy default, the AXA Browser Agent uses these cookies to maintain session context and performance data. These cookies do not include the HttpOnly or Secure flags in certain configurations.
If these cookies cause security compliance failures, disable them in the application profile. Disabling cookies prevents the Browser Agent from storing these specific tokens on the client browser.
If the scanner continues to report the vulnerability after disabling the setting:
For more information refer to the "Configure the Browser Agent Response Decoration"