cancel
Showing results for 
Search instead for 
Did you mean: 

Is SQL Anywhere affected by Apache Log4j vulnerability?

Breck_Carter
Participant

Accepted Solutions (0)

Answers (1)

Answers (1)

chris_keating
Product and Topic Expert
Product and Topic Expert

SQL Anywhere 17 is not affected by this vulnerability.

VolkerBarth
Contributor

What about v16? (It's EOL'ed, I'm aware...)

0 Kudos

The SAP note ("3130849 - CVE-2021-44228 - RCE 0-day exploit found in log4j - SQL Anywhere") states that: "... Note that versions of SQL Anywhere older than 17.0 are not being maintained. If this CVE is a concern, you should upgrade to SQL Anywhere 17.0."

Can you please tell me if there is any information about "zero-day/Log4j2"-vulnerability for SQL Anywhere 16.0.0 and SQL Anywhere 12.0.1?

Breck_Carter
Participant
0 Kudos

AFAIK log4j.jar didn't ship with SQL Anywhere after version 11.