SAP security note 2753595, "SAP Netweaver Business Client does not show warning dialog for specific invalid server certificates", is a note released on June 11, 2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Business Client does not display a warning when accessing web pages with specific invalid HTTPS server certificates. This can lead to:
- Security Risks: The security credentials presented by the server could be forged, going unnoticed by the user.
- Data Confidentiality: Confidentiality of sensitive information entered on a web page could be compromised.
Solution
When using Internet Explorer as the browser control within SAP Business Client, the default behavior of Internet Explorer standalone, as defined in Microsoft Windows Internet Options, is now always applied.
When using Chromium as the browser control within SAP Business Client, a new setting CertificateErrorHandling has been added to the administrator configuration file (%ALLUSERSPROFILE%\SAP\NWBC\NwbcOptions.xml) with the following options:
- UserDecision (default): Allows the user to abort navigations or ignore the certificate error and continue to the navigation target.
- BlockNavigation: Disables the option to continue in the error popup. Every request with invalid certificates will be blocked.
- AllowNavigation: Allows all requests with invalid certificates without displaying any error popup.
Install the patch mentioned in the Support Packages & Patches section, or a newer one, to implement this correction (SAP Business Client patches are cumulative).
CVSS
Score 3.4 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2753595
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
