SAP Knowledge Base Article - Preview

3706969 - CVE-2025-68161 vulnerability in SAP Data Services - SAP Data Services

Symptom

  • CVE-2025-68161 vulnerability is identified in DS server.
  • VA scan results indicate the presence of Apache Log4j versions 2.24.1 in the following paths:
    Plugin name : Apache Log4j 2.0-beta9 < 2.25.3 MitM 
    Plugin Output: 
      Path              : /usr/sap/DataServices/ext/lib/log4j-jcl.jar
      Installed version : 2.24.1
      Fixed version     : 2.25.3

      Path              : /usr/sap/DataServices/ext/lib/log4j-core.jar
      Installed version : 2.24.1
      Fixed version     : 2.25.3 


Read more...

Environment

  • SAP Data Services
  • SAP Cloud Integration for data services

Product

SAP Data Services 2025 ; SAP Data Services 4.3

Keywords

cve-2025-68161, DS, log4j vulnerability, apache log4j, log4j-jcl.jar, log4j-core.jar, fixed version 2.25.3, vulnerability mitigation, data services, third-party software vulnerabilities , KBA , EIM-DS-CON , Connectivity , LOD-HCI-DS-AGNT , On-Premise Agent, Connectivity, Task Run errors , LOD-HCI-DS , HANA Cloud Integration for Data Services , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.