SAP Knowledge Base Article - Preview

3517832 - Security setting in SAP CPI

Symptom

You observed that certain security headers are not being returned to the client and identified this as a potential vulnerability in CPI.


Read more...

Environment

  • SAP Integration Suite
  • SAP Business Technology Platform
  • SAP Cloud Platform Integration

Product

Cloud Integration all versions

Keywords

HTTP, SOAP, X-XSS-Protection, Cross-site Scripting, XSS, VAPT, content-type, prevent, Content-Security-Policy, header, insecure, security, HTML, vulnerability, victim, response body, client, Cloud Integration, x-content-type-options, nosniff, content-type, text/html, Cloud Foundry, CPI, HCI, NEO, CF, SAP Integration Suite, content modifier , KBA , LOD-HCI-PI-CON-HTP , HTTP Adapter , LOD-HCI-PI-OPS , Cloud Operations , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.