Skip links
🔥🔥🔥 Join us for our upcoming training session at Black Hat MEA: "Securing SAP Systems: Expert Insights and Penetration Testing Techniques" 🛡️🔍

3136094 – [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Digital Manufacturing Cloud for Edge Computing

Description

Symptom

SAP DMC Edge uses a version of Open Source component Apache Log4j 2 which is vulnerable to remote code execution (CVE-2021-44228,CVE-2021-45046)

Other Terms

SAP Digital Manufacturing Cloud, SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”), manual activities,Command Injection, OS command injection, Remote Code Execution, Log4j2, CVE-2021-44228, CVE-2021-45046

Reason and Prerequisites

You are running an SAP Digital Manufacturing Cloud solution and have deployed SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”) as part of your solution

Solution

Please Upgrade to the latest hotfix solution as indicated in this note by following the manual activity.

 

Available fix and Supported packages

“`
CTNR-DME-ASSEMBLY-MS|1.0|1.0|
CTNR-DME-DATACOLLECTION-MS|1.0|1.0|
CTNR-DME-DEMAND-MS|1.0|1.0|
CTNR-DME-INVENTORY-MS|1.0|1.0|
CTNR-DME-LABOR-MS|1.0|1.0|
CTNR-DME-NUMBERING-MS|1.0|1.0|
CTNR-DME-WORKINSTRUCTION|1.0|1.0|
CTNR-DMC-DATASYNC-MS|1.0|1.0|
CTNR-DMC-OEE-MS|1.0|1.0|
CNTR-DME-ONBOARDING-MS|1.0|1.0|
CTNR-DME-PLANT-MS|1.0|1.0|
CTNR-DME-PODFOUNDATION-MS|1.0|1.0|
CTNR-DME-PRODUCT-MS|1.0|1.0|
CTNR-DME-PRODUCTION-MS|1.0|1.0|
CTNR-DME-REO-MS|1.0|1.0|
CTNR_FND_MACHINE_MODEL_MS|1.0|1.0|
CTNR_FND_PROC_ENG_MNT_MS|1.0|1.0|
CTNR_DM_FND_PROCESSENGINE|1.0|1.0|

“`

Affected component

N/A

CVSS

CVSS v3.0 Base Score: 10.0/ 10 

Exploit


Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/3136988

TAGS

SAP Digital Manufacturing Cloud, SAP Digital Manufacturing Cloud for edge computing (“DMC Edge”), manual activities,Command Injection, OS command injection, Remote Code Execution, Log4j2, CVE-2021-44228, CVE-2021-45046

RedRays SAP Security Audit

RedRays SAP Security Audit

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer