Web Viewer 12.1 Specifying X-Frame-Options Vulnerabilities

book

Article ID: 74791

calendar_today

Updated On:

Products

CA Output Management Web Viewer

Issue/Introduction

This is an enhancement for Web Viewer to allow specification of new HTTP response headers. 
Some headers maybe added by using Tomcat's filters. But not all headers. 

Environment

Release: 12.1-Output Management-Web Viewer
Component:

Resolution

Apar SO00473 CUMULATIVE BUILD 181 FOR WEB VIEWER 12.1 Introduces the ability to implement new HTTP response headers. 
Apply the latest cumulative maintenance.  Here are directions on how to locate that:
How to locate the latest build (maintenance) for CA Output Management Web Viewer 12.1?

Some headers maybe added by using Tomcat's filters. But not all headers. 

Instructions to implement new HTTP response header(s): 
Add to the bottom of WVProfiles.properties file: 

HEADERRESPONSE.HeaderNames=name1!name1!name3 
HEADERRESPONSE.HeaderValues=value1!value2!value3 
etc. 
and recycle Tomcat.