Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

3136094 – [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Digital Manufacturing Cloud for Edge Computing

Description

Symptom

SAP DMC Edge uses a version of Open Source component Apache Log4j 2 which is vulnerable to remote code execution (CVE-2021-44228,CVE-2021-45046)

Other Terms

SAP Digital Manufacturing Cloud, SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”), manual activities,Command Injection, OS command injection, Remote Code Execution, Log4j2, CVE-2021-44228, CVE-2021-45046

Reason and Prerequisites

You are running an SAP Digital Manufacturing Cloud solution and have deployed SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”) as part of your solution

Solution

Please Upgrade to the latest hotfix solution as indicated in this note by following the manual activity.

 

Available fix and Supported packages

“`
CTNR-DME-ASSEMBLY-MS|1.0|1.0|
CTNR-DME-DATACOLLECTION-MS|1.0|1.0|
CTNR-DME-DEMAND-MS|1.0|1.0|
CTNR-DME-INVENTORY-MS|1.0|1.0|
CTNR-DME-LABOR-MS|1.0|1.0|
CTNR-DME-NUMBERING-MS|1.0|1.0|
CTNR-DME-WORKINSTRUCTION|1.0|1.0|
CTNR-DMC-DATASYNC-MS|1.0|1.0|
CTNR-DMC-OEE-MS|1.0|1.0|
CNTR-DME-ONBOARDING-MS|1.0|1.0|
CTNR-DME-PLANT-MS|1.0|1.0|
CTNR-DME-PODFOUNDATION-MS|1.0|1.0|
CTNR-DME-PRODUCT-MS|1.0|1.0|
CTNR-DME-PRODUCTION-MS|1.0|1.0|
CTNR-DME-REO-MS|1.0|1.0|
CTNR_FND_MACHINE_MODEL_MS|1.0|1.0|
CTNR_FND_PROC_ENG_MNT_MS|1.0|1.0|
CTNR_DM_FND_PROCESSENGINE|1.0|1.0|

“`

Affected component

N/A

CVSS

CVSS v3.0 Base Score: 10.0/ 10 

Exploit


Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/3136988

TAGS

SAP Digital Manufacturing Cloud, SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”), manual activities,Command Injection, OS command injection, Remote Code Execution, Log4j2, CVE-2021-44228, CVE-2021-45046

RedRays SAP Security Audit

RedRays SAP Security Audit

Explore More

RedRays ABAP Security Challenge 2026

WORLD’S FIRST · MAY 30 – 31, 2026 RedRays ABAP Security Challenge 2026 The world’s first security competition for ABAP developers. Write

SAP Security Patch Day – May 2026

SAP has released its May 2026 security patch package containing 15 security notes addressing vulnerabilities across enterprise SAP environments. This release includes