IBM Support

Clickjacking through X-Frame-Option Header

Question & Answer


Question

After a security scan on the Inspector or webreport UI, our scan revealed a vulnerability to Clickjacking by using the X-Frame-Options header. The guidance was along the lines of: "To protect against Clickjacking, it is recommended that any page that contains forms which require a user to enter sensitive information use the X-Frame-Options header set to either DENY or SAMEORIGIN."

[{"Product":{"code":"SSWSR9","label":"IBM InfoSphere Master Data Management"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Component":"--","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"},{"code":"PF035","label":"z\/OS"}],"Version":"All Versions","Edition":"All Editions","Line of Business":{"code":"LOB76","label":"Data Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Product Synonym

MDM;MDM AE;MDM SE;Master Data Management;Master Data Management Advanced Edition;Master Data Management Standard Edition;Hybrid Master Data Management;hybrid MDM;virtual MDM;virtual Master Data Management;physical MDM;physical Master Data Management

Document Information

Modified date:
27 April 2022

UID

swg21988481