The Identity Portal does not have the HttpOnly and Secure attributes for locale cookie
Identity Portal 14.5.x and v15
The only cookie that requires strict HttpOnly and Secure protection is the session cookie which already enforces both.
The locale and userId cookies contain non-sensitive data and therefore do not represent a security risk, regardless of these attribute values.
For JSESSIONID cookie, see the Missing HTTPOnly and Secure Cookie Attribute with IM