Blackbaud CRM, SQL Server Reporting Services Server, and PCI scan failure - Anybody experiencing similar issues

Options
Our Nessus Vulnerability Scan is reporting that the SQL Server Reporting Services Server is missing HSTS (Strict-Transport-Security) in the HTTP Header.
 
This vulnerability is checked typically for HTTPS (Web) Servers. Although the SSRS is not a full fledge Web Server (No IIS installation), it is still using the HTTPS traffic.
 
Microsoft provides the steps for HSTS configuration for IIS webserver but not for previous versions of SSRS. The latest SSRS which is 2019 seems to have this configuration but I believe the latest Blackbaud CRM cannot yet support the SSRS 2019.
 
 
Plugin Name: HSTS Missing From HTTPS Server 
Plugin #: 84502 
Description: The remote HTTPS server is not enforcing HTTP Strict Transport Security (HSTS). The lack of HSTS allows downgrade attacks, SSL stripping man-in-the-middle attacks, and weakens cookie-hijacking protections. 

 
 

 

Categories