<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: HTTP Security Header Not Detected in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/http-security-header-not-detected/qaa-p/12267804#M4595403</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;SAP Note &lt;A href="https://launchpad.support.sap.com/#/notes/2860209" target="_blank"&gt;2860209&lt;/A&gt; enables the X-Xss-protection header for WEBGUI (Handler CL_HTTP_EXT_ITS_2, used in new releases).&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cris&lt;/P&gt;</description>
    <pubDate>Wed, 26 Aug 2020 22:34:27 GMT</pubDate>
    <dc:creator>cris_hansen</dc:creator>
    <dc:date>2020-08-26T22:34:27Z</dc:date>
    <item>
      <title>HTTP Security Header Not Detected</title>
      <link>https://community.sap.com/t5/technology-q-a/http-security-header-not-detected/qaq-p/12267801</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
  &lt;P&gt;"HTTP Security Header Not Detected" is one of many security vulnerabilities from third party network scan. As per the solution provided, I need to set proper X frame option, X-Xss-protection, X-content-type-option and strict-transport-security. Our env consists of Fiori and ECC system. Any idea where to set these settings to fix this vulnerability? &lt;/P&gt;
  &lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:27:23 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/http-security-header-not-detected/qaq-p/12267801</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2020-08-25T16:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Security Header Not Detected</title>
      <link>https://community.sap.com/t5/technology-q-a/http-security-header-not-detected/qaa-p/12267802#M4595401</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Check SAP Note &lt;A href="https://launchpad.support.sap.com/#/notes/2202116" target="_blank"&gt;2202116&lt;/A&gt;           -          Support of HTTP Strict Transport Security.&lt;/P&gt;&lt;P&gt;If you share the SAP_BASIS version and SP level, then I can see about the other headers.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cris&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:45:19 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/http-security-header-not-detected/qaa-p/12267802#M4595401</guid>
      <dc:creator>cris_hansen</dc:creator>
      <dc:date>2020-08-25T16:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Security Header Not Detected</title>
      <link>https://community.sap.com/t5/technology-q-a/http-security-header-not-detected/qaa-p/12267803#M4595402</link>
      <description>&lt;P&gt;Thanks. I will check the note.&lt;/P&gt;&lt;P&gt;SAP_BASIS is on 740 Sp16&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 17:11:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/http-security-header-not-detected/qaa-p/12267803#M4595402</guid>
      <dc:creator>former_member706793</dc:creator>
      <dc:date>2020-08-25T17:11:39Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Security Header Not Detected</title>
      <link>https://community.sap.com/t5/technology-q-a/http-security-header-not-detected/qaa-p/12267804#M4595403</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;SAP Note &lt;A href="https://launchpad.support.sap.com/#/notes/2860209" target="_blank"&gt;2860209&lt;/A&gt; enables the X-Xss-protection header for WEBGUI (Handler CL_HTTP_EXT_ITS_2, used in new releases).&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cris&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 22:34:27 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/http-security-header-not-detected/qaa-p/12267804#M4595403</guid>
      <dc:creator>cris_hansen</dc:creator>
      <dc:date>2020-08-26T22:34:27Z</dc:date>
    </item>
  </channel>
</rss>

