Certificate Management missing from J2SE AE 7.10

[] [] [] [] [] [] []

Symptom
Certificate Management link not present in J2SE AE 7.10
Other terms
J2SE, Certificate Management, Security
Reason and Prerequisites
Incorrect implementation of Certificate Management functionality.
Solution
Kindly apply this patch to rectify the error mentioned above.

Security Note: Session Forwarding by URL

[] [] [] [] [] [] [] []

Symptom
An URL, which has been received for example by e-mail, enables a user to connect with the SAP system.
Other terms
Security vulnerability, Session Riding
Reason and Prerequisites
The system is not configured for the HTTP Security Session, see transaction SICF_SESSIONS.
The application, which can be accessed, uses the “stateful-http-communication”. This means the session with the backend is kept [...]

SOAMANAGER security – signature certificate not for for SAML

[] [] [] [] [] [] [] []

Symptom
After creating a logical port out of a WSDL containing SAML authentication in the SOAMANAGER the user is asked to provide a signature certificate in the logical port.
Other terms
SOAMANAGER, SOA, Security, Signature, Certificate
Reason and Prerequisites
Coding error, missing if statement.
Solution
Workaround: Don’t supply the signature certificate. The Web Service call will work still. For message [...]