Skip to Main Content

APEX

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

Session ID visible in URL in Oracle APEX (ORDS) – How to remove or secure it?

I am working on an application in Oracle APEX (version 24.1) deployed via ORDS, and I am facing an issue related to session ID exposure in the URL.

The application URL contains a session parameter like:

https://abc.com:8443/ords/r/app/page?session=XXXXXXXXXXXX

As part of a security assessment, this has been flagged as:

Session Token leakage within URL query (High Risk)

Any guidance, best practices, or official recommendations would be very helpful.

Comments
Post Details
Added 8 hours ago
9 comments
152 views