Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

3136094 – [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Digital Manufacturing Cloud for Edge Computing

Description

Symptom

SAP DMC Edge uses a version of Open Source component Apache Log4j 2 which is vulnerable to remote code execution (CVE-2021-44228,CVE-2021-45046)

Other Terms

SAP Digital Manufacturing Cloud, SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”), manual activities,Command Injection, OS command injection, Remote Code Execution, Log4j2, CVE-2021-44228, CVE-2021-45046

Reason and Prerequisites

You are running an SAP Digital Manufacturing Cloud solution and have deployed SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”) as part of your solution

Solution

Please Upgrade to the latest hotfix solution as indicated in this note by following the manual activity.

 

Available fix and Supported packages

“`
CTNR-DME-ASSEMBLY-MS|1.0|1.0|
CTNR-DME-DATACOLLECTION-MS|1.0|1.0|
CTNR-DME-DEMAND-MS|1.0|1.0|
CTNR-DME-INVENTORY-MS|1.0|1.0|
CTNR-DME-LABOR-MS|1.0|1.0|
CTNR-DME-NUMBERING-MS|1.0|1.0|
CTNR-DME-WORKINSTRUCTION|1.0|1.0|
CTNR-DMC-DATASYNC-MS|1.0|1.0|
CTNR-DMC-OEE-MS|1.0|1.0|
CNTR-DME-ONBOARDING-MS|1.0|1.0|
CTNR-DME-PLANT-MS|1.0|1.0|
CTNR-DME-PODFOUNDATION-MS|1.0|1.0|
CTNR-DME-PRODUCT-MS|1.0|1.0|
CTNR-DME-PRODUCTION-MS|1.0|1.0|
CTNR-DME-REO-MS|1.0|1.0|
CTNR_FND_MACHINE_MODEL_MS|1.0|1.0|
CTNR_FND_PROC_ENG_MNT_MS|1.0|1.0|
CTNR_DM_FND_PROCESSENGINE|1.0|1.0|

“`

Affected component

N/A

CVSS

CVSS v3.0 Base Score: 10.0/ 10 

Exploit


Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/3136988

TAGS

SAP Digital Manufacturing Cloud, SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”), manual activities,Command Injection, OS command injection, Remote Code Execution, Log4j2, CVE-2021-44228, CVE-2021-45046

RedRays SAP Security Audit

RedRays SAP Security Audit

Explore More

RedRays AI for ABAP Code Security

Empowering Secure, Efficient, and Compliant SAP ABAP Development—in Real Time and Without Data Retention In today’s rapidly evolving business landscape, organizations increasingly

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.