Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

3136094 – [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Digital Manufacturing Cloud for Edge Computing

Description

Symptom

SAP DMC Edge uses a version of Open Source component Apache Log4j 2 which is vulnerable to remote code execution (CVE-2021-44228,CVE-2021-45046)

Other Terms

SAP Digital Manufacturing Cloud, SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”), manual activities,Command Injection, OS command injection, Remote Code Execution, Log4j2, CVE-2021-44228, CVE-2021-45046

Reason and Prerequisites

You are running an SAP Digital Manufacturing Cloud solution and have deployed SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”) as part of your solution

Solution

Please Upgrade to the latest hotfix solution as indicated in this note by following the manual activity.

 

Available fix and Supported packages

“`
CTNR-DME-ASSEMBLY-MS|1.0|1.0|
CTNR-DME-DATACOLLECTION-MS|1.0|1.0|
CTNR-DME-DEMAND-MS|1.0|1.0|
CTNR-DME-INVENTORY-MS|1.0|1.0|
CTNR-DME-LABOR-MS|1.0|1.0|
CTNR-DME-NUMBERING-MS|1.0|1.0|
CTNR-DME-WORKINSTRUCTION|1.0|1.0|
CTNR-DMC-DATASYNC-MS|1.0|1.0|
CTNR-DMC-OEE-MS|1.0|1.0|
CNTR-DME-ONBOARDING-MS|1.0|1.0|
CTNR-DME-PLANT-MS|1.0|1.0|
CTNR-DME-PODFOUNDATION-MS|1.0|1.0|
CTNR-DME-PRODUCT-MS|1.0|1.0|
CTNR-DME-PRODUCTION-MS|1.0|1.0|
CTNR-DME-REO-MS|1.0|1.0|
CTNR_FND_MACHINE_MODEL_MS|1.0|1.0|
CTNR_FND_PROC_ENG_MNT_MS|1.0|1.0|
CTNR_DM_FND_PROCESSENGINE|1.0|1.0|

“`

Affected component

N/A

CVSS

CVSS v3.0 Base Score: 10.0/ 10 

Exploit


Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/3136988

TAGS

SAP Digital Manufacturing Cloud, SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”), manual activities,Command Injection, OS command injection, Remote Code Execution, Log4j2, CVE-2021-44228, CVE-2021-45046

RedRays SAP Security Audit

RedRays SAP Security Audit

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,