Log4Shell (Log4j -gap) & SAP Business One
17 Dec

Log4Shell (Log4j gap) & SAP Business One

A security vulnerability "Log4Shell" (CVE-2021-44228) was categorised as extremely critical on 10.12.02021 by the German Federal Office for Security (BSI) with the level red. Software components can also be affected by the Log4j vulnerability in connection with SAP Business One.

Log4j with gaps

The name Log4Shell refers to the fact that the vulnerability exists in a widely used Java code library called Log4j (Logging for Java). Attackers can exploit this vulnerability to gain the ability to execute any system code of their choice.
In other words, without the need for a login and/or password or other access barriers, hackers could use a harmless request to hijack servers. They are then tricked into logging in, downloading code that contains malware.

SAP Business One affected by Log4Shell

SAP has identified 32 applications affected by CVE-2021-44228. As of yesterday, Patch Tuesday, the software manufacturer has already patched 20 of these applications and is still working feverishly on further fixes. SAP Business One is also affected. SAP has already published write a notet (an S user is required), which mainly relates to the SAP Business One 10 version.

The following components are affected:

  • workflow
  • License Server
  • Service Layer
  • Job Service
  • Extension Manager
  • Integration Framework (B1i)

All-clear for MariProject regarding Log4Shell

Log4Shell is for MARIProject, one of the major extensions for SAP Business One, is not a problem according to the manufacturer. MARIProject largely dispenses with the use of Java and is therefore not affected by the Log4j gap. This applies in particular to the web client and mobile client, web service and RESTService.

Coresuite also not affected

The all-clear can also be given for Coresystems products.

The following software products are not affected:

  • Coresuite and its modules
  • Coresuite Service
  • Coresuite Cube
  • SAP B1 Cloud Connector

The following products were found to be using Log4J. Appropriate patches or recommended temporary fixes have been applied:
SAP Field Service Management
As FSM is a cloud-based solution, no action is required on the part of the customer.

CKS DIGITAL leaves Log4Shell cold

There is a global rejection of any effects from C.K. Solutions. Neither CKS.DMS, CKS.ADC, CKS.EINVOICE, CKS.WEB, CKS.SUISSQR or CKS.RUN are affected by "Log4Shell" in any way.

COBISOFT not affected by log4j zero-day vulnerability.

The solutions from COBISOFT ( COBI.time, COBI.wms, COBI.ppc, Cobi.edi, Cobi.msv) are not affected by the loophole in Log4j.

Boyum also on the outside

The Boyum support portal now also states that none of the products in the Boyum family use Log4j software and that they are therefore not affected by the security vulnerability.

UPDATE

With 11.1.2022, SAP has fixed the problem related to the Apache Log4j vulnerabilities in SAP Business One. In order to apply the solution, existing SAP Business One installations must be updated to version 10 FP2111.
With the published patch, SAP no longer recommends using the workaround described above (SAP Note/KBA 3131789).


One Day, the Whole B1 Ecosystem: Solution Day Connect Comes to Almere / Amsterdam

One Day, the Whole B1 Ecosystem: Solution Day Connect Comes to Almere / Amsterdam

On October 22, 2026, the SAP Business One community will meet in Almere for a full day of demos, fresh ideas...
LATS

LATS: Considering several paths simultaneously with AI — and the availability check in SAP B1

This series focuses on artificial intelligence in conjunction with SAP Business One. Not as a collection of product announcements, but as...
Service Layer AI as a transactional layer

SAP B1 10.0 FP2608: Service Layer AI as a transactional layer

The SAP Business One Service Layer has previously served predominantly as a passive data provider: applications requested data via OData, each ...
SAP Business One – new patch

SAP Business One 10.0 Feature Package 2608 / FP2608 Part 3

Feature Package 2608 (FP26608) introduces several new apps to the SAP Business One Web Client. They relate to internal ...
SAP Business One – new patch

SAP Business One 10.0 Feature Package 2608 / New Features & Functions – Part 2

Feature Package 2608 introduces several new assistants and management apps to the SAP Business One Web Client. They concern purchase quotations, ...
SAP Business One – new patch

SAP Business One 10.0 FP 2608 / New Features & Functions – Part 1

Function package FP 2608 enhances SAP Business One 10.0 in three areas that users will notice directly in their day-to-day operations. The Web ...
Wird geladen …