SAP Knowledge Base Article - Public

2969802 - RMK Vulnerability report states "Content Security Policy (CSP) Missing" - Recruiting Marketing

Symptom

You have received a report from a Partner or a 3rd Party provides stating that your Career Site shows a vulnerability described as: "Content Security Policy (CPS) Missing" and the recommendation might be to "Enable CPS headers".

Environment

SAP SuccessFactors Recruiting Marketing (RMK)

Resolution

Content Security Policy (CSP) header can be enabled for RMK career sites in Career Site Builder (CSB). Please refer to the Following KBA 3044364 - Enabling Content Security Policy for RMK Site - Recruiting Marketing to check the steps to how to configure this feature.

See Also

3044364 - Enabling Content Security Policy for RMK Site - Recruiting Marketing 

Enabling the Content Security Policy for a Career Site

Keywords

Content Security Policy (CPS) Missing, CSP, Vulnerability, CSP Header, RMK, Career Site, CSB , KBA , LOD-SF-RMK-SEC , Security & Vulnerabilities , Problem

Product

SAP SuccessFactors Recruiting all versions