Update 2021-12-16:

Keep an eye on this SAP source for ongoing updates!
Shortcut to latest State of Document:
https://support.sap.com/content/dam/support/en_us/library/ssp/my-support/trust-center/sap-tc-01-5025...
---------
Dear community,
the security vulnerability of the Log4J framework is attracting a lot of attention.
We are just wondering if neoSDK is also affected by this vulnerability.
Java Web Tomcat 8:
First investigations showed that e.g. neoSDK version 3.80.13 uses Log4J version 1.2.16.
Also in the newest 3.142.7 it seems, that there is Log4J 1.2.16 used.

Java Web Tomcat 9:

According to heise.de, 1.2.x versions should not be affected.
So we assume that there is no need for action.
Do we understand this correctly?
Alternatively, and to be on the safe side, the following JVM argument could also be specified at application startup to disable the malicious functionality
–Dlog4j2.formatMsgNoLookups=True
Attention: The application must be restarted for this.
The configuration can be done via the BTP Cockpit:
[Removed by the moderator.]
Thanks and many greetings
Mario
Disclaimer: This is not safety advice and I take no responsibility for its accuracy.
Request clarification before answering.
In short, do the following:
Check SAP’s Response to CVE-2021-44228 Apache Log4j Vulnerability:
And there use the information provided at:
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.