Oracle HTTP Server Recommendations to Prevent Cross-Site Scripting (XSS) Attacks
(Doc ID 2370975.1)
Last updated on APRIL 08, 2021
Oracle HTTP Server - Version 22.214.171.124.0 and later Oracle Fusion Middleware - Version 126.96.36.199.0 and later Information in this document applies to any platform.
Some security scans may be requesting an action for these line items:
XSS Content-Security-Policy X-XSS-Protection
These are set as http headers to take advantage of browser XSS attack prevention features. This document is provided from an Oracle HTTP Server perspective to help application developers and administrators mitigate Cross-Site Scripting (XSS) attacks. The information within also applies to any other situations where Oracle HTTP Server is not present.
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!