Advisory
On 08.02.2022 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within None.
SAP Note 3139893 addresses "[CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Dynamic Authorization Management" to prevent none with a hot news risk for exploitation.
A workaround does exist, according to SAP Security Advisory team. It is advisable to implement the correction as none, the team suggests.
Risk specification
NoneSolution
None Circumstances exist that prevent the timely installation of a patch provided by the manufacturer. In such cases, you may consider applying the suggested workaround as a temporary or compensating mitigation: "None".
The advisory is valid for
- NEXTLABSCONTROLCENTERSERVER 9.1.0.0
- NEXTLABSCONTROLCENTERSERVER 2021.03
- NEXTLABSJAVAPOLICYCONTROLLE 9.1.0.0
- NEXTLABSJAVAPOLICYCONTROLLE 2021.03