Oracle Weblogic Server (MOSC)

MOSC Banner

HSTS Missing From HTTPS Server (RFC 6797) Vul in WebLogic v12.2.1.4

edited Jan 18, 2023 1:28PM in Oracle Weblogic Server (MOSC) 1 commentAnswered

Hi Team,

We are receiving "HSTS Missing From HTTPS Server (RFC 6797)" vulnerability in WebLogic v12.2.1.4. Currently we are running with April 2022 Patch for WebLogic 12.2.1.4.

Could you please suggest us, do we need to go and apply with latest patch for WebLogic 12.2.1.4 to remediate this "HSTS Missing From HTTPS Server (RFC 6797)" vulnerability?

also do we need update -Dweblogic.http.headers.enableHSTS=true in the WebLogic JVM class path argument's?


Appreciate for your response...

Regards,

Sudhakar

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center