My Oracle Support Banner

Oracle HTTP Server Recommendations to Prevent Cross-Site Scripting (XSS) Attacks (Doc ID 2370975.1)

Last updated on AUGUST 20, 2019

Applies to:

Oracle HTTP Server - Version 11.1.1.7.0 and later
Oracle Fusion Middleware - Version 11.1.1.7.0 and later
Information in this document applies to any platform.

Purpose

Some security scans may be requesting an action for these line items:

XSS Content-Security-Policy
X-XSS-Protection

These are set as http headers to take advantage of browser XSS attack prevention features. This document is provided from an Oracle HTTP Server perspective to help application developers and administrators mitigate Cross-Site Scripting (XSS) attacks.  The information within also applies to any other situations where Oracle HTTP Server is not present.

Details

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Purpose
Details
 What are XSS attacks ?
 When do they occur?
 What happens in an XSS attack?
 How to prevent such attacks?
 Summary
References

My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.