Skip to Main Content

APEX

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

OWAPS Scan Vulnerabilities in Apex Application

DiviyaSep 25 2017 — edited Oct 4 2017

Hi,

As part of our product security scanning, related to XSS Cross-site scripting (reflected) vulnerability, we were told that the application should not be returning “text/html”.

In the page source , we found the following line

<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />

Based on the suggestion to implement the change as mentioned in the article https://community.oracle.com/thread/441269, we tried but it does not work as expected.

Please let us know how we can overwrite the above content type in our application.

Comments
Locked Post
New comments cannot be posted to this locked post.
Post Details
Locked on Nov 1 2017
Added on Sep 25 2017
2 comments
571 views