---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Escape xml response

# Escape xml response {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Manage how XML escapes are handled on your instance.
Use this property to manage if XML responses are escaped. If the property is set to the recommended value of false, then XML responses will not be escaped which can lead to XML injection attack. The injection
of unintended XML content into an XML message can alter the intended logic of an application.

## More information {#sc-escape-xml-response__section_ghv_dvg_1xb}

{#sc-escape-xml-response__table_hhv_dvg_1xb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.soaprequest.unescape_xml_response |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | false |
| Default value | false |
| Category | [Validation, sanitization, and encoding](https://servicenow-prod.fluidtopics.net/F1nREUr0FIKK6cga6jbKwg "Validation, sanitization, and encoding addresses input validation to prevent against vulnerabilities like Cross-Site Scripting (XSS), SQL injection and other attacks.") |
| Security risk | * Severity score: 6.4 * CVSS score: Medium * Security risk details: Setting this property to false disables XML escaping, which could lead to XML injection attack. {#sc-escape-xml-response__ul_ihv_dvg_1xb} |
| Dependencies and prerequisites | None |
[ ]

{#sc-escape-xml-response__table_hhv_dvg_1xb}

