cancel
Showing results for 
Search instead for 
Did you mean: 
Subscribe

Update 2021-12-16:

Keep an eye on this SAP source for ongoing updates!

Shortcut to latest State of Document:
https://support.sap.com/content/dam/support/en_us/library/ssp/my-support/trust-center/sap-tc-01-5025...

---------

Dear community,

the security vulnerability of the Log4J framework is attracting a lot of attention.
We are just wondering if neoSDK is also affected by this vulnerability.

Java Web Tomcat 8:
First investigations showed that e.g. neoSDK version 3.80.13 uses Log4J version 1.2.16.
Also in the newest 3.142.7 it seems, that there is Log4J 1.2.16 used.

Java Web Tomcat 9:

According to heise.de, 1.2.x versions should not be affected.

So we assume that there is no need for action.
Do we understand this correctly?

Alternatively, and to be on the safe side, the following JVM argument could also be specified at application startup to disable the malicious functionality

–Dlog4j2.formatMsgNoLookups=True

Attention: The application must be restarted for this.

The configuration can be done via the BTP Cockpit:

[Removed by the moderator.]

Thanks and many greetings

Mario

Disclaimer: This is not safety advice and I take no responsibility for its accuracy.

View Entire Topic
mario_guenter91
Participant
0 Likes