Symptom
A vulnerability assessment or security scan of the SAP PI/PO AS Java system reports the following finding:
CVE-2026-34477
Path : /usr/sap/SID/<instance>/j2ee/cluster/bin/ext/com.sap.aii.adapter.ws.cxf.lib/lib/org.apache.logging.log4j-log4j-core-<current_version>.jar
Installed version : <current_version>
Fixed version : 2.25.4
CVE-2026-34478
Path : /usr/sap/SID/<instance>/j2ee/cluster/bin/ext/com.sap.aii.adapter.ws.cxf.lib/lib/org.apache.logging.log4j-log4j-core-<current_version>.jar
Installed version : <current_version>
Fixed version : 2.25.4
CVE-2026-34480
/usr/sap/SID/<instance>/j2ee/cluster/bin/ext/com.sap.aii.adapter.ws.cxf.lib/lib/org.apache.logging.log4j-log4j-core-<current_version>.jar
Installed version : <current_version>
Fixed version : 2.25.4
and would like to understand whether SAP PI/PO is affected by this vulnerability and whether a correction, patch, or workaround is available for the SAP-delivered component containing the reported Log4j library.
Read more...
Environment
SAP Netweaver 7.5
SAP Process Integration/Orchestration 7.5
Product
Keywords
CVE-2026-34478, CVE-2026-34480, CVE-2026-34477, vulnerability, PI, PO , KBA , BC-XI-CON-JWS , Java Web Service Adapter , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview