cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

HTTP Security Header Not Detected

Former Member
3,046

Hi,

"HTTP Security Header Not Detected" is one of many security vulnerabilities from third party network scan. As per the solution provided, I need to set proper X frame option, X-Xss-protection, X-content-type-option and strict-transport-security. Our env consists of Fiori and ECC system. Any idea where to set these settings to fix this vulnerability?

Thanks

View Entire Topic
cris_hansen
Product and Topic Expert
Product and Topic Expert
0 Likes

Hello,

Check SAP Note 2202116 - Support of HTTP Strict Transport Security.

If you share the SAP_BASIS version and SP level, then I can see about the other headers.

Regards,

Cris