We are pleased to announce a security enhancement whereby nosniff header response code is automatically used by Oracle E-Business Suite Releases 12.2 and 12.1.3.

Allowing the browser to guess the MIME type of a file provides attackers the ability to trick the browser into executing malicious content. Using nosniff header response code tells the browser to strictly interpret the MIME type of the file and to not guess MIME type based on the content. 

Requirements

This feature is automatically enabled for all Oracle E-Business Suite Release 12.2.x and 12.1.3 customers who apply the October 2018 or higher Critical Patch Update (CPU).   

References

Related Articles