cancel
Showing results for 
Search instead for 
Did you mean: 

HTTP Security Header Not Detected

former_member275479
Participant

Hi,

"HTTP Security Header Not Detected" is one of many security vulnerabilities from third party network scan. As per the solution provided, I need to set proper X frame option, X-Xss-protection, X-content-type-option and strict-transport-security. Our env consists of Fiori and ECC system. Any idea where to set these settings to fix this vulnerability?

Thanks

Accepted Solutions (0)

Answers (2)

Answers (2)

former_member706793
Participant
0 Kudos

Thanks. I will check the note.

SAP_BASIS is on 740 Sp16

cris_hansen
Advisor
Advisor
0 Kudos

Hello,

SAP Note 2860209 enables the X-Xss-protection header for WEBGUI (Handler CL_HTTP_EXT_ITS_2, used in new releases).

Regards,

Cris

cris_hansen
Advisor
Advisor
0 Kudos

Hello,

Check SAP Note 2202116 - Support of HTTP Strict Transport Security.

If you share the SAP_BASIS version and SP level, then I can see about the other headers.

Regards,

Cris