I just read blog How to Protect AS ABAP & AS Java Against BEAST Attacks
Now I have some further question about ssl/ciphersuites. When I set it to 129:HIGH scan report says that "A vulnerability exists in SSL 3.0 and TLS 1.0 that could allow information disclosure if an attacker intercepts encrypted traffic served from an affected system." Recommendation is to use TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode. How can I set up that on SAP ECC?