cancel
Showing results for 
Search instead for 
Did you mean: 

HTTP Security Header Not Detected

08-25-2020 6:27 PM
3146 views 3 comments
SAP Managed Tags
Subscribe

Hi,

"HTTP Security Header Not Detected" is one of many security vulnerabilities from third party network scan. As per the solution provided, I need to set proper X frame option, X-Xss-protection, X-content-type-option and strict-transport-security. Our env consists of Fiori and ECC system. Any idea where to set these settings to fix this vulnerability?

Thanks

Accepted Solutions (0)

Answers (2)

Answers (2)

former_member706793
Participant
0 Likes

Thanks. I will check the note.

SAP_BASIS is on 740 Sp16

cris_hansen
Product and Topic Expert
Product and Topic Expert
0 Likes

Hello,

SAP Note 2860209 enables the X-Xss-protection header for WEBGUI (Handler CL_HTTP_EXT_ITS_2, used in new releases).

Regards,

Cris

cris_hansen
Product and Topic Expert
Product and Topic Expert
0 Likes

Hello,

Check SAP Note 2202116 - Support of HTTP Strict Transport Security.

If you share the SAP_BASIS version and SP level, then I can see about the other headers.

Regards,

Cris