SAP Knowledge Base Article - Preview

3137930 - CVE-2021-4104 & other log4j vulnerabilities - further information for BI 4.x

Symptom

  • Further information on the following log4j vulnerabilities:
    CVE-2019-17571 (SocketServer.class -> SAP Note 2914574)
    CVE-2020-9488 (SMTPAppender.class -> SAP Note 2914574)
    CVE-2021-4104 (JMSAppender.class -> SAP Note 2914574)
    CVE-2021-44832 (JDBCAppender.class -> SAP Note 2914574)
    CVE-2022-23302 (JMSSink.class -> SAP Note 2914574)
    CVE-2022-23305 (JDBCAppender.class -> SAP Note 2914574)
    CVE-2022-23307 (Chainsaw -> SAP Note 2914574)


Read more...

Environment

  • SAP BusinessObjects Business Intelligence (BI) Platform 4.x (4.2 / 4.3)
  • SAP BusinessObjects BI Support Tool 
  • log4j

Product

SAP BusinessObjects Business Intelligence platform 4.2 ; SAP BusinessObjects Business Intelligence platform 4.3

Keywords

SAP Business Objects, log4j, JMSSink.class, JDBCAppender.class, Chainsaw, SMTPAppender.class, SocketServer.class, BI, BOE, BIPST, BIST, BusinessObjects, BI support tool, CVE, vulnerability, CVE-2019-17571, CVE-2020-9488, CVE-2021-4104, CVE-2021-44832, CVE-2022-23302, CVE-2022-23305, CVE-2022-23307, CVE-2023-26464 , KBA , BI-BIP-DEP , Webapp Deployment, Networking, Vulnerabilities, Webservices , BI-BIP-ST , Support Tool , BI-BIP-SEC , Security Vulnerabilities in SAP BusinessObjects , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.