We are pleased to announce a security enhancement whereby nosniff header response code is automatically used by Oracle E-Business Suite Releases 12.2 and 12.1.3.
Allowing the browser to guess the MIME type of a file provides attackers the ability to trick the browser into executing malicious content. Using nosniff header response code tells the browser to strictly interpret the MIME type of the file and to not guess MIME type based on the content.
Requirements
This feature is automatically enabled for all Oracle E-Business Suite Release 12.2.x and 12.1.3 customers who apply the October 2018 or higher Critical Patch Update (CPU).
References
- Identifying the Latest Critical Patch Update for Oracle E-Business Suite Release 12 (MOS Note 248400.1)
- Oracle E-Business Suite Release 12 Critical Patch Update (October 2018) (MOS Note 2445688.1)
- FAQ: Oracle E-Business Suite Security (MOS Note 2063486.1)
