---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Set Xframe options to prevent embedding third-party websites \[Updated in Security Center 1.3\]

# Set Xframe options to prevent embedding third-party websites \[Updated in Security Center
1.3\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Configure this property to prevent the content of a web-application from being embedded in a third-party site.
If com.glide.cs.embed.xframe_options is not set to the recommended
value of DENY or SAMEORIGIN, then content of the web application could be embedded in a
third-party site using an ALLOW-FROM uri. Allowing untrusted third-party sites could enable
attacks such as clickjacking.

## More information {#sc-xframe-options__section_qhx_1b1_xwb}

{#sc-xframe-options__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | com.glide.cs.embed.xframe_options |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | string |
| Recommended value | sameorigin |
| Default value | sameorigin |
| Category | [Configuration](https://servicenow-prod.fluidtopics.net/s9Iz8esR6282THUNXoEpzg "The Configuration category ensures applications have a secure build environment and hardened third party library components. Specifically, ensuring a build and deploy pipeline is repeatable and includes automated testing and prevents known security issues from being deployed. This includes keeping dependencies up to date and free from known vulnerabilities.") |
| Security risk | * Severity score: 3.1 * CVSS score: Low * Security risk details: Not setting this property to the recommended value could enable the content of a web application to be embedded in a third-party site enabling attacks such as click-jacking. {#sc-xframe-options__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | None |
[ ]

{#sc-xframe-options__table_ajc_b43_3kb}

