Skip links

3136094 – [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Digital Manufacturing Cloud for Edge Computing

Description

Symptom

SAP DMC Edge uses a version of Open Source component Apache Log4j 2 which is vulnerable to remote code execution (CVE-2021-44228,CVE-2021-45046)

Other Terms

SAP Digital Manufacturing Cloud, SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”), manual activities,Command Injection, OS command injection, Remote Code Execution, Log4j2, CVE-2021-44228, CVE-2021-45046

Reason and Prerequisites

You are running an SAP Digital Manufacturing Cloud solution and have deployed SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”) as part of your solution

Solution

Please Upgrade to the latest hotfix solution as indicated in this note by following the manual activity.

 

Available fix and Supported packages

“`
CTNR-DME-ASSEMBLY-MS|1.0|1.0|
CTNR-DME-DATACOLLECTION-MS|1.0|1.0|
CTNR-DME-DEMAND-MS|1.0|1.0|
CTNR-DME-INVENTORY-MS|1.0|1.0|
CTNR-DME-LABOR-MS|1.0|1.0|
CTNR-DME-NUMBERING-MS|1.0|1.0|
CTNR-DME-WORKINSTRUCTION|1.0|1.0|
CTNR-DMC-DATASYNC-MS|1.0|1.0|
CTNR-DMC-OEE-MS|1.0|1.0|
CNTR-DME-ONBOARDING-MS|1.0|1.0|
CTNR-DME-PLANT-MS|1.0|1.0|
CTNR-DME-PODFOUNDATION-MS|1.0|1.0|
CTNR-DME-PRODUCT-MS|1.0|1.0|
CTNR-DME-PRODUCTION-MS|1.0|1.0|
CTNR-DME-REO-MS|1.0|1.0|
CTNR_FND_MACHINE_MODEL_MS|1.0|1.0|
CTNR_FND_PROC_ENG_MNT_MS|1.0|1.0|
CTNR_DM_FND_PROCESSENGINE|1.0|1.0|

“`

Affected component

N/A

CVSS

CVSS v3.0 Base Score: 10.0/ 10 

Exploit


Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/3136988

TAGS

SAP Digital Manufacturing Cloud, SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”), manual activities,Command Injection, OS command injection, Remote Code Execution, Log4j2, CVE-2021-44228, CVE-2021-45046

RedRays SAP Security Audit

RedRays SAP Security Audit

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer

Initiating SAP Penetration Testing

►   Pentest, short for penetration testing, refers to a set of processes that simulate an attacker’s actions to identify security vulnerabilities. Companies

SAP Security Patch Day RedRays

May 2024 SAP Security Patch Day

Vulnerability: Multiple vulnerabilities in SAP CX Commerce SAP Component: CEC-SCC-PLA-PL CVE ID: CVE-2019-17495 CVSS Score: 9.8 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Category: Program error