---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Auto set content type options \[Removed in Security Center 1.3.3\]

# Auto set content type options \[Removed in Security Center 1.3.3\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Configure the Auto set content type options property on your instance to prevent MIME confusion attacks.
Use this property to control the X-Content-Type-Options response HTTP header. The X-Content-Type-Options response HTTP header is used by the server to indicate that the MIME types advertised in the Content-Type headers should
be followed. If this property is set to
false, then
it is possible for an attacker to conduct MIME confusion attacks;
if set to
true then this
header will prevent the browser from interpreting files as anything but the content type in the HTTP headers.  
Warnung:  
The value for this property is a no DB override. It can't be altered or overridden.

## More information {#sc-auto-set-content-type-options__section_more_information}

{#sc-auto-set-content-type-options__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.security.header.auto_set_x_content_type_options |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | true |
| Default value | false |
| Category | [Configuration](https://servicenow-prod.fluidtopics.net/s9Iz8esR6282THUNXoEpzg "The Configuration category ensures applications have a secure build environment and hardened third party library components. Specifically, ensuring a build and deploy pipeline is repeatable and includes automated testing and prevents known security issues from being deployed. This includes keeping dependencies up to date and free from known vulnerabilities.") |
| Security risk | * Severity score: 7.3 * CVSS score: High * Security risk details: Setting this property to false could make it possible for an attacker to conduct MIME confusion attacks. {#sc-auto-set-content-type-options__ul_pzq_pcf_ywb} |
| Dependencies and prerequisites | None |
| References | [Add a system property](https://www.servicenow.com/docs/access?context=t_AddAPropertyUsingSysPropsList&version=australia&pubname=australia-platform-administration&ft:locale=en-US) |
[ ]

{#sc-auto-set-content-type-options__table_ajc_b43_3kb}

