Skip to Main Content

APEX

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

Customize response header on APEX AJAX

Currently we get feedback from pen-tester and they are returning some vulnerability result as below:

Link Affected: https://<hostname>/<ords>/wwv_flow.ajax/*

i. Missing HTTP "Strict-Transport-Security" Header

ii. Missing "X-XSS-Protection" Header

iii. Missing "X-Content-Type-Options" Header

From the result above,

i.  Able to set customize response header via oracle APEX ? 

ii. If yes, possible to customize on dynamic action?

Comments
Post Details
Added on Jun 17 2020
0 comments
232 views