HPE OneView
1824638 Members
4665 Online
109672 Solutions
New Discussion

OneView for vCenter Security vulnerability

 
msobers22
Trusted Contributor

OneView for vCenter Security vulnerability

The OneView for vCenter instance for my customer was flagged during a Qualys security scan for the following.

Qualys QID: 11827 HTTP Security Header not detected.

Has anyone seen that before and know how to fix the vulnerability?

They are using version 11.4

 

Thanks in advance

2 REPLIES 2
Suman_1978
HPE Pro

Re: OneView for vCenter Security vulnerability

Hi,

I think its more to do with VMware or Qualys, rather than OneView.

Have you consulted VMware or Qualys regarding this issue?
https://success.qualys.com/support/s/article/000006279
https://success.qualys.com/support/s/article/000006387
https://success.qualys.com/discussions/s/question/0D52L00004To0WSSAZ/how-does-one-resolve-qid11827-http-security-header-not-detected-for-vmware-esxi-670-build-16075168

Thank You!
I work with HPE but opinions expressed here are mine.



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
pirx
Valued Contributor

Re: OneView for vCenter Security vulnerability

If Qualys reports this for OV4VC its clearly and OV4VC or Qualys issue. But why should this be a VMware issue?