<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HSTS Not Enforced on Remote Web Server for DMT.EM Component (Servers: Server 1, Server 2) in SAS Viya</title>
    <link>https://communities.sas.com/t5/SAS-Viya/HSTS-Not-Enforced-on-Remote-Web-Server-for-DMT-EM-Component/m-p/967522#M2861</link>
    <description>&lt;DIV class=""&gt;&lt;STRONG&gt;To SAS Viya Support Team,&lt;/STRONG&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;Greetings,&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;During a security scan, we identified a critical vulnerability on the following servers where &lt;STRONG&gt;HSTS (HTTP Strict Transport Security) is not enforced&lt;/STRONG&gt; on the remote web server for the &lt;STRONG&gt;DMT.EM component&lt;/STRONG&gt;, in violation of RFC 6797:&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;1. Vulnerability Details&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Component/Service&lt;/STRONG&gt;: DMT.EM&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Vulnerability Description&lt;/STRONG&gt;: The remote web server does not enforce HSTS, leaving it susceptible to man-in-the-middle (MITM) attacks.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Affected Servers&lt;/STRONG&gt;:&lt;UL&gt;&lt;LI&gt;Server 1&lt;/LI&gt;&lt;LI&gt;Server 2&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Vulnerability ID&lt;/STRONG&gt;: 42&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Remediation Recommendation&lt;/STRONG&gt;: Configure the remote web server to enforce HSTS.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;2. Requested Assistance&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Please advise on the &lt;STRONG&gt;specific steps&lt;/STRONG&gt; to enable HSTS for the DMT.EM component in the SAS Viya environment, including any configuration files or settings that need modification.&lt;/LI&gt;&lt;LI&gt;Confirm whether this requires changes to the SAS Viya configuration or can be addressed at the web server level (e.g., Apache, Nginx).&lt;/LI&gt;&lt;LI&gt;Provide guidance on verifying the successful implementation of HSTS post-configuration (e.g., using browser tools or security headers checkers).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;3. Severity and Timeline&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;This vulnerability poses a high risk to data security. We kindly request a &lt;STRONG&gt;priority response&lt;/STRONG&gt; and a detailed action plan by &lt;STRONG&gt;[Insert Deadline, e.g., 24 hours from ticket creation]&lt;/STRONG&gt;.&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;Thank you for your prompt support.&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;Best regards,&lt;/DIV&gt;&lt;DIV class=""&gt;West&lt;/DIV&gt;</description>
    <pubDate>Tue, 27 May 2025 02:58:10 GMT</pubDate>
    <dc:creator>west_liu</dc:creator>
    <dc:date>2025-05-27T02:58:10Z</dc:date>
    <item>
      <title>HSTS Not Enforced on Remote Web Server for DMT.EM Component (Servers: Server 1, Server 2)</title>
      <link>https://communities.sas.com/t5/SAS-Viya/HSTS-Not-Enforced-on-Remote-Web-Server-for-DMT-EM-Component/m-p/967522#M2861</link>
      <description>&lt;DIV class=""&gt;&lt;STRONG&gt;To SAS Viya Support Team,&lt;/STRONG&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;Greetings,&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;During a security scan, we identified a critical vulnerability on the following servers where &lt;STRONG&gt;HSTS (HTTP Strict Transport Security) is not enforced&lt;/STRONG&gt; on the remote web server for the &lt;STRONG&gt;DMT.EM component&lt;/STRONG&gt;, in violation of RFC 6797:&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;1. Vulnerability Details&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Component/Service&lt;/STRONG&gt;: DMT.EM&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Vulnerability Description&lt;/STRONG&gt;: The remote web server does not enforce HSTS, leaving it susceptible to man-in-the-middle (MITM) attacks.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Affected Servers&lt;/STRONG&gt;:&lt;UL&gt;&lt;LI&gt;Server 1&lt;/LI&gt;&lt;LI&gt;Server 2&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Vulnerability ID&lt;/STRONG&gt;: 42&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Remediation Recommendation&lt;/STRONG&gt;: Configure the remote web server to enforce HSTS.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;2. Requested Assistance&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Please advise on the &lt;STRONG&gt;specific steps&lt;/STRONG&gt; to enable HSTS for the DMT.EM component in the SAS Viya environment, including any configuration files or settings that need modification.&lt;/LI&gt;&lt;LI&gt;Confirm whether this requires changes to the SAS Viya configuration or can be addressed at the web server level (e.g., Apache, Nginx).&lt;/LI&gt;&lt;LI&gt;Provide guidance on verifying the successful implementation of HSTS post-configuration (e.g., using browser tools or security headers checkers).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;3. Severity and Timeline&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;This vulnerability poses a high risk to data security. We kindly request a &lt;STRONG&gt;priority response&lt;/STRONG&gt; and a detailed action plan by &lt;STRONG&gt;[Insert Deadline, e.g., 24 hours from ticket creation]&lt;/STRONG&gt;.&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;Thank you for your prompt support.&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;Best regards,&lt;/DIV&gt;&lt;DIV class=""&gt;West&lt;/DIV&gt;</description>
      <pubDate>Tue, 27 May 2025 02:58:10 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Viya/HSTS-Not-Enforced-on-Remote-Web-Server-for-DMT-EM-Component/m-p/967522#M2861</guid>
      <dc:creator>west_liu</dc:creator>
      <dc:date>2025-05-27T02:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: HSTS Not Enforced on Remote Web Server for DMT.EM Component (Servers: Server 1, Server 2)</title>
      <link>https://communities.sas.com/t5/SAS-Viya/HSTS-Not-Enforced-on-Remote-Web-Server-for-DMT-EM-Component/m-p/967523#M2862</link>
      <description>&lt;P&gt;To get a priority response open a ticket via the Tech Support channel:&amp;nbsp;&lt;A href="https://service.sas.com/" target="_blank"&gt;https://service.sas.com/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 04:08:51 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Viya/HSTS-Not-Enforced-on-Remote-Web-Server-for-DMT-EM-Component/m-p/967523#M2862</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2025-05-27T04:08:51Z</dc:date>
    </item>
  </channel>
</rss>

