SAP Knowledge Base Article - Preview

3709194 - Impact of CVE-2025-68161 on PI/PO Java Web Service Adapter

Symptom

  • A security scan, using some third party scanning tool, reports a potential security vulnerability impacting a file which appears to below to the 
  • In this case, the CVE-2025-68161 
  • Suspect vulnerable file path is: /usr/sap/<SID>/<Instance>/j2ee/cluster/bin/ext/com.sap.aii.adapter.ws.cxf.lib/lib/org.apache.logging.log4j-log4j-core-2.23.1.jar
    Installed version : 2.23.1
    Fixed version : 2.25.3


Read more...

Environment

SAP NetWeaver 7.5

Product

SAP NetWeaver all versions

Keywords

Scanner, security scanning, Process Integration, Process Orchestration, Java Web Service Adapter, JWS , KBA , BC-XI-CON-JWS , Java Web Service Adapter , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.