Jde Groot334794 (Community Member) asked a question.

CWE ID 693, which response headers are required?

Our code was scanned and "Protection Mechanism Failure (CWE ID 693)" was reported as a vulnerability. The description is: One or more recommended response headers are absent or set to insecure values. These response headers are necessary to enable specific defense mechanisms in compliant web browsers.

 

Which response headers need to be added to pass this?


  • kmorrison (Veracode)

    No, that should be it, but the scanner will flag this for any traffic that is missing this header. This could include intermediate pages or a landing page after a successful or failed login. It might be worth contacting Veracode support to have someone look at your specific flaw. You can contact support here in the community from the log-in drop-down menu in the upper right, or through the Veracode platform from the 'contact support' link at the bottom of every page. Be sure to include a link to your scan and all details of your question.

    Expand Post
    Selected as Best
  • Jde Groot334794 (Community Member)

    Thanks for your help! Are there any other headers? We already have X-Frame-Options set to SAMEORIGIN but the scan still reported this issue

  • kmorrison (Veracode)

    No, that should be it, but the scanner will flag this for any traffic that is missing this header. This could include intermediate pages or a landing page after a successful or failed login. It might be worth contacting Veracode support to have someone look at your specific flaw. You can contact support here in the community from the log-in drop-down menu in the upper right, or through the Veracode platform from the 'contact support' link at the bottom of every page. Be sure to include a link to your scan and all details of your question.

    Expand Post
    Selected as Best

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.