cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1230
Views
0
Helpful
6
Replies

New FTD 7.26 installation Vulnerability: Missing httpOnly Cookie

cball111
Level 1
Level 1

Can anyone tell me how they have remediated this issue? I cant seem to find ANYthing on it after numerous searches. We have the VPN portal on our FTD, and our most recent vuln. scan returned the above finding.

6 Replies 6

I tried creating the FlexConfig as you mentioned, unfortunately the deploy returns an error each time.

I upgraded our FTDs/FMC to 7.2.7, but am still getting an error when I try to deploy the HTTPOnly FlexConfig: 

 

error :
@httpOnly
^
ERROR: % Invalid input detected at '^' marker.
Config Error -- @httpOnly

 

I then tried it without the @ symbol, and cannot save it to the object:

cball111_0-1717777040354.png

 

cball111_1-1717777197295.png

 

Salman Mahajan
Cisco Employee
Cisco Employee

FYI -We will be providing a UI option to enable the 'HTTP Only Flag' in FMC 7.7, which is the targeted release for next year.

Hey Salman!

Did the HTTP Only Flag in the UI happen? 

 

Ken