ACR : ACR Vulnerability issue and need to configure the remote web server to use HSTS


Doc ID    SOLN386800
Version:    1.0
Status:    Published
Published date:    16 Jul 2026
Author:   
shivakirangp
 

Details

ACR : ACR Vulnerability issue and need to configure the remote web server to use HSTS

Problem Clarification

Applies ACR 15.x

Custoemr reported below vulnerability:

Vulnerability : HSTS Missing From HTTPS Server (RFC 6797)

Details: The remote web server is not enforcing HSTS, as defined by RFC 6797.
HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking protections.

Cause

Customer requested a feature to enable ACR to transmit the HSTS header

Solution

Checked with the development team, and they recommend adding the following property to enable ACR to emit the HSTS header:

Set viewerx.secure=true in the properties file, and then restart ACR.

Also, if you want this property to take effect immediately, before applying it in acr.properties file and restarting acr, you can set this property in the ACR maintenance page as well by logging in using https://ServerIpAddress:8443/servlet/acr?cmd=mtce

Setting the property in the maintenance page is a temporary solution, the permanent solution is to set the property in acr.properties file and restart the ACR.

Avaya -- Proprietary. Use pursuant to the terms of your signed agreement or Avaya policy