Symptom
- The following vulnerability can be reported by a scan report:
CVE-2026-49844
"Plugin Output:
Path : /sybase/<SID>/ASE-16_0/lib/log4j-core-2.17.1.jar
Installed version : 2.17.1
Fixed version : 2.25.5
Path : /sybase/<SID>/WLA/lib/log4j-core-2.23.1.jar
Installed version : 2.23.1
Fixed version : 2.25.5
Path : /sybase/<SID>/WS-16_0/lib/log4j-core-2.23.1.jar
Installed version : 2.23.1
Fixed version : 2.25.5
Path : /sybase/<SID>/WS-16_0/lib/log4j-jcl-2.23.1.jar
Installed version : 2.23.1
Fixed version : 2.25.5
Path : /sybase/<SID>/shared/lib/log4j-core-2.17.1.jar
Installed version : 2.17.1
Fixed version : 2.25.5
Path: /sybase/<SID>/COCKPIT-4/common/lib/log4j-core-2.17.1.jar
Installed version: 2.17.1
Fixed version: 2.25.5
Note: This last Path is related to deprecated ASE Cockpit tool, which has been replaced by the AMC tool and was never used for ASE Business Suite installations. This path has been removed from ASE 16.1 SP00 PL01 onward. Refer to KBA 2905660 - SAP Adaptive Server Enterprise Cockpit End of Life
- You would like to know if any potential impact of that Log4j vulnerability CVE-2026-49844 on SAP Adaptive Server Enterprise (SAP ASE).
Read more...
Environment
SAP Adaptive Server Enterprise (ASE) 16.x
Product
Keywords
Log4j, log4j2, Log4Shell, JSON logging, JNDI injection, remote code execution, RCE, Apache Log4j, CVE-2026-49844, SAP ASE, SAP Adaptive Server Enterprise, 16.0 SP04, PL07, HF1, security, vulnerability assessment, not affected, not impacted. , KBA , BC-DB-SYB , Business Suite on Adaptive Server Enterprise , BW-SYS-DB-SYB , BW on Adaptive Server Enterprise , BC-SYB-ASE , Sybase ASE Database Platform (non Business Suite) , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview