SAP Knowledge Base Article - Preview

3792934 - Vulnerability CVE-2021-44228 (Log4j) detected in Portal - SAP PD

Symptom

  • Security audit reports vulnerability CVE-2021-44228 (Log4Shell) in Apache Log4j.
  • Recommended remediation from audit: upgrade to Apache Log4j version 2.16.0.
  • Example file paths flagged by audits:
       C:\Program Files\SAP\PowerDesigner Portal 16\Tomcat\webapps\powerdesigner-web\WEB-INF\lib\log4j-core-2.13.3.jar
       C:\Program Files\SAP\PowerDesigner Portal 16\Tomcat\webapps\powerdesigner-web.war


Read more...

Environment

  • SAP PowerDesigner Web 16.7
  • Apache Log4j version earlier than 2.16.x

Product

SAP PowerDesigner all versions

Keywords

powerdesigner, portal, web, cmr, tomcat, vulnerability, CVE, CVE-2021-44228, log4shell, log4j , KBA , BC-SYB-PD , PowerDesigner , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.