Prevent Clickjacking attacks by implementing X-Frame-Options

  • 7021131
  • 29-Jul-2017
  • 16-Aug-2017

Environment

Micro Focus Filr 3

Situation

Some pages in the Filr web interface are rendered using iFrames without any added security provided by the X-Frame-Options. The X-Frame-Options can be used to avoid Clickjacking attacks by ensuring that their content is not embedded into other sites.

Resolution

A fix for this issue is available in the Filr 3.2.1 Update. The X-Frame-Options value SAMEORIGIN has been implemented to provide added security for Filr pages that are rendered using iFrames.