SAP Knowledge Base Article - Preview

3795554 - Apache Log4j 1.x End-of-Life Library Is Detected in an SAP Server

Symptom

A vulnerability scan identifies an End-of-Life Apache Log4j 1.x library on an SAP server and reports it as a Critical security finding.

The scanner reports the following details:

  • Installed version: 1.2.13
  • Security End of Life: August 5, 2015
  • Time since Security End of Life: >= 10 years
  • File location: contains /cybersafe.com/

The reported vulnerabilities are related to the outdated Apache Log4j 1.x library.


Read more...

Environment

  • SAP NetWeaver
  • SAP Process Integration

Product

SAP NetWeaver all versions ; SAP Process Integration all versions

Keywords

Apache Log4j, Log4j 1.x, Log4j 1.2.13, Apache Log4j vulnerability, Log4j End of Life, Log4j EOL SAP, Cybersafe, Cybersafe Log4j, third-party Log4j library, SAP server Log4j vulnerability, vulnerability scan detects Apache Log4j 1.x, Apache Log4j 1.x vulnerability on SAP server , KBA , BC-XI-CON , Connectivity , BC-JAS-SEC , Security, User Management , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.