Last updated on JUNE 21, 2017
Applies to:Business Intelligence Server Enterprise Edition - Version 220.127.116.11.0 and later
Information in this document applies to any platform.
What does the field #BadCssChars do and why is the recommendation to have it blank?
As per banking industry standard, we put these values in the #BadCssChars variable during configuration to avoid Cross Site Scripting (CSS) attacks:
<,>,',%22 (4 characters)
and not the one suggested in the note, which is to keep this value blank.
Sign In with your My Oracle Support account
Don't have a My Oracle Support account? Click to get started
My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms