Log4J vulnerability

Current situation for SAP PI/PO/CPI/Cloud Connector

SAP Cloud Connector – OK

SAP has now confirmed that the SAP Cloud Connector is not affected by Log4J.

3130868 – CVE-2021-44228 – SAP Cloud Connector Impact

SAP CPI – ACTION REQUIRED

SAP is asking its SAP CPI customers to check tenants for Log4j on their own.

By default, Log4J is not used. Only through custom development or custom adapters, it can come to use.

Here you can find a blog how to easily check the system accordingly:

https://blogs.sap.com/2021/12/14/scan-your-cloud-integration-tenant-for-log4j-libraries-with-cpilint/

SAP PI/PO/NetWeaver – ACTION REQUIRED

SAP has now issued a note regarding Log4J in relation to the SAP NetWeaver Java Stack.

Please check urgently if your systems are affected according to the note and take action if necessary.

3129883 – https://launchpad.support.sap.com/#/notes/3129883

You need support?

We will be happy to assist you with our certified colleagues.