SAP Knowledge Base Article - Preview

2939065 - X-Frame-Options Header not set in BI Launchpad and CMC logon page

Symptom

Code Scanning report / tool reflects "X-Frame-Options Header not set" alert for BI Launchpad and CMC logon page:
https://<hostname>:<tomcat port>/BOE/CMC
https://<hostname>:<tomcat port>/BOE/BI


Read more...

Environment

SAP BusinessObjects BI Platform 4.x (4.0 / 4.1 / 4.2)

Product

SAP BusinessObjects Business Intelligence platform 4.0 ; SAP BusinessObjects Business Intelligence platform 4.1 ; SAP BusinessObjects Business Intelligence platform 4.2

Keywords

BI 4.x 4.0, 4.1 4.2 X-FRAME OPTIONS OWASP ZAP Scanning Report security vulnerability login page BIP BI Platform Central Management Console application , KBA , BI-BIP-CMC , Central Management Console (CMC) , BI-BIP-INV , InfoView, BI launch pad , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.