HPE OneView
1824984 Members
3484 Online
109678 Solutions
New Discussion

Re: OneView for vCenter Security vulnerability

 
msobers22
Trusted Contributor

OneView for vCenter Security vulnerability

The OneView for vCenter instance for my customer was flagged during a Qualys security scan for the following.

Qualys QID: 11827 HTTP Security Header not detected.

Has anyone seen that before and know how to fix the vulnerability?

They are using version 11.4

 

Thanks in advance

2 REPLIES 2
Suman_1978
HPE Pro

Re: OneView for vCenter Security vulnerability

Hi,

I think its more to do with VMware or Qualys, rather than OneView.

Have you consulted VMware or Qualys regarding this issue?
https://success.qualys.com/support/s/article/000006279
https://success.qualys.com/support/s/article/000006387
https://success.qualys.com/discussions/s/question/0D52L00004To0WSSAZ/how-does-one-resolve-qid11827-http-security-header-not-detected-for-vmware-esxi-670-build-16075168

Thank You!
I work with HPE but opinions expressed here are mine.



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
pirx
Valued Contributor

Re: OneView for vCenter Security vulnerability

If Qualys reports this for OV4VC its clearly and OV4VC or Qualys issue. But why should this be a VMware issue?