SAP Knowledge Base Article - Preview

3782334 - Log4j vulnerability in PI/PO system

Symptom

A vulnerability assessment or security scan of the SAP PI/PO AS Java system reports the following finding:

CVE-2026-34477
Path : /usr/sap/SID/<instance>/j2ee/cluster/bin/ext/com.sap.aii.adapter.ws.cxf.lib/lib/org.apache.logging.log4j-log4j-core-<current_version>.jar
Installed version : <current_version>
Fixed version : 2.25.4

CVE-2026-34478 
Path : /usr/sap/SID/<instance>/j2ee/cluster/bin/ext/com.sap.aii.adapter.ws.cxf.lib/lib/org.apache.logging.log4j-log4j-core-<current_version>.jar
Installed version : <current_version>
Fixed version : 2.25.4

CVE-2026-34480
/usr/sap/SID/<instance>/j2ee/cluster/bin/ext/com.sap.aii.adapter.ws.cxf.lib/lib/org.apache.logging.log4j-log4j-core-<current_version>.jar
Installed version : <current_version>
Fixed version : 2.25.4

and would like to understand whether SAP PI/PO is affected by this vulnerability and whether a correction, patch, or workaround is available for the SAP-delivered component containing the reported Log4j library.




Read more...

Environment

SAP Netweaver 7.5
SAP Process Integration/Orchestration 7.5

Product

SAP NetWeaver 7.5

Keywords

CVE-2026-34478, CVE-2026-34480, CVE-2026-34477, vulnerability, PI, PO , KBA , BC-XI-CON-JWS , Java Web Service Adapter , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.