HSTS Missing From HTTPS Server (RFC 6797) Vul in WebLogic v12.2.1.4
Hi Team,
We are receiving "HSTS Missing From HTTPS Server (RFC 6797)" vulnerability in WebLogic v12.2.1.4. Currently we are running with April 2022 Patch for WebLogic 12.2.1.4.
Could you please suggest us, do we need to go and apply with latest patch for WebLogic 12.2.1.4 to remediate this "HSTS Missing From HTTPS Server (RFC 6797)" vulnerability?
also do we need update -Dweblogic.http.headers.enableHSTS=true in the WebLogic JVM class path argument's?
Appreciate for your response...
Regards,
Sudhakar