Sage City Announcement:
Sage was alerted (Friday 10th December 2021) to a critical remote code execution vulnerability within all Apache log4j versions 2.0-beta9 to 2.15
References
https://logging.apache.org/log4j/2.x/security.html
https://www.ncsc.gov.uk/news/apache-log4j-vulnerability
A vulnerability rated with a Critical impact is one which could potentially be exploited by a remote attacker to get Log4j to execute arbitrary code (either as the user the server is running as, or root). These are the sorts of vulnerabilities that could be exploited automatically by worms.
The Sage 100 Development Team has investigated this, and the Apache Log4J 2 library is NOT used in the supported 2021, 2020, and 2019 versions of Sage 100. The Sage 100 SPC portal and landing page also do not use the Apache Log4J library and are not impacted.
For customers using Sage 100 with Sage CRM, Sage CRM have produced patches which are currently being tested and we will advise on results and availability as soon as possible. The Quick Entry Sales Order integration feature does use the Log4J 1 library but the Log4J 1 library is not affected by this vulnerability. Additionally, customers using Sage Intelligence reporting components of Sage 100 have also been investigated and cleared at this time. Sage Fixed Assets and Sage HRMS have also been cleared.
Finally, The SAP team has confirmed there is no impact on Crystal Reports, and Aatrix, which we use for payroll e-filing, has published this statement that they are also not impacted (aatrix.com/log4j)
It is important to note that while Sage has confirmed as many of our integrated applications and services as possible, applications and services provided by independent software vendors may still have vulnerabilities. Customers should work with their reseller to ensure that their systems are secure.
References
https://access.redhat.com/security/cve/cve-2021-44228
https://solr.apache.org/news.html
https://launchpad.support.sap.com/#/notes/3129956
Please watch the following Sage City links for news: https://www.sagecity.com/us/sage100_erp/f/sage-100-announcements-news-tips
------------------------------
Kevin Moyes
Technical Systems Analyst
Munjal White Consulting Co.
Toronto ON
------------------------------
Original Message:
Sent: 12-17-2021 10:59
From: Gary Feldman
Subject: Log4J Vulnerability
SAP BusinessObjects BI Platform is not impacted by the CVE-2021-44228.
Environment
- SAP BusinessObjects Business Intelligence (BI) Platform 4.2, 4.3
- SAP BusinessObjects Business Intelligence (BI) Platform 4.0 / 4.1 * NO LONGER SUPPORTED
- SAP BusinessObjects Business Intelligence (BI), Edge edition 4.2, 4.3
- SAP BusinessObjects Business Intelligence (BI), Edge edition 4.0 / 4.1 * NO LONGER SUPPORTED
- SAP BusinessObjects BI Platform Client Tools 4.2, 4.3
- SAP BusinessObjects BI Platform Client Tools 4.0, 4.1 * NO LONGER SUPPORTED
- SAP Crystal Server 2016, 2020
- SAP Crystal Reports 2016, 2020
- SAP Crystal Reports for Enterprise 4.2, 4.3
- BI Platform Support Tool (BIPST)
- Live Office
- Universe Design Tool (UDT)
- Analysis for Office (AO) and Analysis for Office Add-on for BI Platform
- Lumira Discovery, Lumira Server for BI Platform & Lumira Designer
- SAP Design Studio * NO LONGER SUPPORTED
- SAP BI Mobile server
- All dependent server tools like Upgrade Management Tool, Promotion Management Wizard, Wdeploy
- All Operating Systems
------------------------------
Gary Feldman
Cloud Evangelist
I-Business Network, LLC
Marietta GA
http://www.summithosting.com
------------------------------
Original Message:
Sent: 12-16-2021 17:00
From: Brett Zimmerman
Subject: Log4J Vulnerability
From Sage:
Important update: Apache Log4j vulnerabilityDear Partner,
I want to update you on the Apache Log4j vulnerability that was initially announced on Friday, December 10, 2021, with a subsequent issue being reported on Dec. 15. This is being widely reported as one of the most serious and widespread security vulnerabilities ever discovered-potentially billions of devices and services are at risk. Security and IT teams around the world have spent the last few days attempting to understand and remediate it.
The very largest companies such as Microsoft, Apple, Cisco, and many others have been impacted (even games such as Minecraft)-there are very few companies unaffected because the Log4j library is so ubiquitous.
Impact to Sage
As with all large organizations, the vulnerable Log4j component is present in Sage's technology environments, and teams across the business are working around the clock to mitigate the risk. Good visibility of impacted and potentially impacted services has been achieved, but the investigation continues across all areas.
Sage is in the process of patching its internal systems. We are continuing to work at pace on Sage product areas that have the potential to be exposed to this vulnerability. As patches become available for Sage products, they will be made available in the usual way through our support sites.
Updates on Sage products we have patched · Three online product/services use the vulnerable version of Log4j (Payments Acceptance, Compliance Service and Maxwell Service). All three were protected by tailored web application firewall rules from December 10 and were patched over the weekend-there is no action needed from customers or partners. Sage products with potential vulnerability · Sage CRM is the only desktop product known to be affected. The manual mitigation published by Apache will eliminate this. Patches have been produced for impacted versions including (2020 R2, 2021 R1, and 2021 R2) and are at the test stage. As soon as the patch is through QA and available to customers, we will issue this through the usual channels. · Sage X3 software is not exposed to the log4j vulnerability; however, Sage X3 integrates natively with a third-party solution called Elasticsearch. Sage X3 versions 11 and 12 are likely to be integrated with impacted instances of Elasticsearch (e.g. version 7.9 and above), but not exposed if our published security best practices have been followed.
We encourage our customers and partners to review their Elasticsearch installation and follow the security applicable remediation from this provider. Please note that information and guidance on Sage X3 security best practices are available in the Sage X3 online help. Logon to the Sage Partner Hub to view the FAQ. It's important that we show up for our customers consistently-please see below a holding statement for use when supporting customers or on your customer-facing support sites.
Best regards
Nancy Teixeira VP Partner Strategy and Sales Sage |
|
Customer support statement"Sage and its partners take the security of its customer solutions extremely seriously and regularly undertakes proactive testing across its products to identify potential vulnerabilities and provide fixes. Following the initial announcement of the Apache Log4j vulnerability on December 10, 2021, and subsequent updates, Sage has been investigating the potential impact on our products and services.
Our initial findings indicate there are no exposed systems in the Sage products or architecture stack that uses log4j. Where we have identified the potential for vulnerability, we have issued an initial patch. We are proactively monitoring the situation and applying and supplying new patches if required.
However, working with our industry peers and in an abundance of caution, we are upgrading our version of log4j in all areas of our business that use this third-party component.
If you have further questions, please speak to your account manager in the first instance. We thank you for your patience in this matter." |
|
------------------------------
Brett Zimmerman
Net at Work
Greater Boston Area
Original Message:
Sent: 12-15-2021 19:00
From: Moira Goggin
Subject: Log4J Vulnerability
There is a list of affected software released by the Dutch National Cyber Security Center - it does list SAP as noted above. For Sage products, I'd be concerned about Sage CRM since Apache is affected.
https://github.com/NCSC-NL/log4shell/tree/main/software
------------------------------
Moira Goggin
Chismet Consulting Corp.
Long Beach CA
Original Message:
Sent: 12-15-2021 14:33
From: Brett Zimmerman
Subject: Log4J Vulnerability
Re: impact to other Sage 100 related products:
------------------------------
Brett Zimmerman
Net at Work
Greater Boston Area
Original Message:
Sent: 12-15-2021 09:38
From: Mark Chinsky
Subject: Log4J Vulnerability
5 Days ago and Sage hasn't updated that post. Makes you wonder how much Sage really knows about the software they sell/own.
 | | | Mark Chinsky | | Partner | | Clients First Business Solutions |
|
| | | | a: | | 670 North Beers St. Bldg 4, 2nd Fl. | , | Holmdel | , | NJ | | 07733 |
|
| Your Best Interest is Our Purpose
|
|
|
|
|
| ++++ | ............................................................................................................................................................................. |
|
 |
Original Message:
Sent: 12/15/2021 9:32:00 AM
From: Wayne Schulz
Subject: RE: Log4J Vulnerability
So far as I've seen these are the resources that Sage has regarding the Log4J vulnerability:
OVERVIEW ( WHAT IS LOG4J ? )
'Extremely bad' vulnerability found in widely used logging system ( The Verge )
Guidance for preventing, detecting, and hunting for CVE-2021-44228 Log4j 2 exploitation ( Microsoft )
SAGE 100 SPECIFIC
What impact does the Log4j vulnerability have on Sage 100? - ( KB 113754 )
Apache Log4j vulnerability - December 2021 - ( KB 113775 )
Log4j and Sage 100 vulnerability? ( Sage City )
SAGE CRM SPECIFIC
Advisory: Apache log4j vulnerability (CVE-2021-45046) - ( Sage City )
------------------------------
Wayne Schulz
Schulz Consulting
860-516-8990