Sage 100

 View Only
Expand all | Collapse all

Log4J Vulnerability

  • 1.  Log4J Vulnerability

    Posted 12-13-2021 12:00

    It appears there's not much chatter thus far re: 'Log4J Vulnerability' and Sage 100.  But based on this SAP forum thread, specifically the post near the bottom by Don (SAP employee), this does not impact Crystal Reports – i.e. "We've discussed this over the weekend and it does not impact CR or CR for VS or BOE runtime at all.  Yes our version is out of date and we are working on updating it but there is no impact to .NET runtime since it's not used.  So you can ignore the the warning."
    Sage City - Log4j and Sage 100 vulnerability?



    ------------------------------
    Brett Zimmerman
    Net at Work
    Greater Boston Area
    ------------------------------


  • 2.  RE: Log4J Vulnerability

    Posted 12-13-2021 12:03
    Edited by Brett Zimmerman 12-13-2021 12:13

    New post in the SAP thread above:  

    Here is the official answer from SAP (updated 13/12/2021 Ver. 3)
      • SAP BusinessObjects BI Platform is not impacted by the CVE-2021-44228
      • The impacted component is the main JNDI package. JNDI classes and methods are not used in the SAP BusinessObjects BI Platform.
      • Further security / mitigation against Remote Code Execution is available at the Java level in 8u121 and 8u191, therefore we recommend customers to be on a version of SAP BusinessObjects BI Platform that packages at least a version > 8u121. Therefore we recommend the minimum version that should be applied is 4.2 SP05. For more information about the versions of SAPJVM (and which Oracle JVM version they are based on) supplied per BI version, see:
        2914488 - List of Bundled SAP JVM versions shipped with selected Patches of SAP BusinessObjects Business Intelligence Platform 4.x


    ------------------------------
    Brett Zimmerman
    Net at Work
    Greater Boston Area
    ------------------------------



  • 3.  RE: Log4J Vulnerability

    Posted 12-13-2021 13:09
    I have had two customer IT departments contact me this morning asking for a fix.  They both indicate that the Sage application itself is using this vulnerable Apache logging library.  I'm not sure where to go with this.  Is this something a Sage Consultant should be addressing or is it an "IT" thing?  

    BTW - I tried to open the KB link above, but it requires a login

    ------------------------------
    Stacey Moody
    Consultant
    Emerald TC
    Johns Creek GA
    (678) 697-3093
    ------------------------------



  • 4.  RE: Log4J Vulnerability

    Posted 12-13-2021 13:38
    I'm not sure but someone may have taken a screen shot and pasted the SAP KB 



    ------------------------------
    Wayne Schulz
    Schulz Consulting
    860-516-8990
    ------------------------------



  • 5.  RE: Log4J Vulnerability

    Posted 12-14-2021 11:56

    KB article re: Sage 100: 

    What impact does the Log4j vulnerability have on Sage 100?
    Created on 12-13-2021 | Last modified on 12-14-2021
    Summary
    What impact does the Log4j vulnerability have on Sage 100?
    Is the Sage 100 server vulnerable to the Log4j vulnerability?
    Resolution
      • Sage Engineering has been made aware of the Log4j vulnerability on Friday Dec 10 and is currently researching if there is any affect for Sage 100. While it's unlikely Sage 100 is affected, Sage Engineering is currently researching this and will provide an update when the research is complete.
    Keywords: 
    Product: Sage 100
    Solution ID: 113754
    Published on: 12-14-2021
    Applies to: Download and installation >  Installation


    ------------------------------
    Brett Zimmerman
    Net at Work
    Greater Boston Area
    ------------------------------



  • 6.  RE: Log4J Vulnerability

    Posted 12-14-2021 14:36
    With Sage's 'bolt on every 3rd party option' possible, this has to be a big task. Think of all the Sage resold/'blessed' applications.  Each of those vendors needs to do some digging, ASAP.  This issue is so dangerous that even 24 hours is too long to notify and patch.

    ------------------------------
    Mark Chinsky
    Clients First Business Solutions
    ------------------------------



  • 7.  RE: Log4J Vulnerability

    Posted 12-14-2021 16:33
    Thanks so much!  I missed it on the KB.

    ------------------------------
    Mary Mays
    Sr. Consultant, DSD Business Systems
    DSD Business Systems
    Goddard KS
    316-269-4264
    ------------------------------



  • 8.  RE: Log4J Vulnerability

    Posted 12-14-2021 16:34
    Thanks for posting this.

    ------------------------------
    Mary Mays
    Sr. Consultant, DSD Business Systems
    DSD Business Systems
    Goddard KS
    316-269-4264
    ------------------------------



  • 9.  RE: Log4J Vulnerability

    Posted 12-15-2021 09:32
    Edited by Wayne Schulz 12-17-2021 12:54
    So far as I've seen these are the resources that Sage has regarding the Log4J vulnerability: 

    OVERVIEW ( WHAT IS  LOG4J ? )
    'Extremely bad' vulnerability found in widely used logging system ( The Verge )
    Guidance for preventing, detecting, and hunting for CVE-2021-44228 Log4j 2 exploitation ( Microsoft )

    SAGE 100 SPECIFIC
    What impact does the Log4j vulnerability have on Sage 100? - ( KB 113754 )
    Apache Log4j vulnerability - December 2021 - ( KB 113775 )
    Log4j and Sage 100 vulnerability? ( Sage City )
    Advisory: Apache log4j vulnerability (CVE-2021-44228) ( Sage City - 12/17/20221

    SAGE CRM SPECIFIC
    Advisory: Apache log4j vulnerability (CVE-2021-45046) - ( Sage City )
    It appears that patches for Sage CRM might be limited to only the current supported versions.
    It is unknown yet what can be done for older Sage CRM versions ( aside from upgrading )

    ------------------------------
    Wayne Schulz
    Schulz Consulting
    860-516-8990
    ------------------------------



  • 10.  RE: Log4J Vulnerability

    Posted 12-15-2021 09:39

    5 Days ago and Sage hasn't updated that post.  Makes you wonder how much Sage really knows about the software they sell/own.

    Mark Chinsky
    Partner
    Clients First Business Solutions
    t: (732) 497-9915 | e: mchinsky@clientsfirst-us.com
    w: www.clientsfirst-us.com
    a: 
    670 North Beers St. Bldg 4, 2nd Fl.HolmdelNJ 07733
    Your Best Interest is Our Purpose
    ++++.............................................................................................................................................................................
    Is Your Data EverSafe?





  • 11.  RE: Log4J Vulnerability

    Posted 12-15-2021 14:34
    Re: impact to other Sage 100 related products:

    ​​

    ------------------------------
    Brett Zimmerman
    Net at Work
    Greater Boston Area
    ------------------------------



  • 12.  RE: Log4J Vulnerability

    Posted 12-15-2021 19:00
    There is a list of affected software released by the Dutch National Cyber Security Center - it does list SAP as noted above.  For Sage products, I'd be concerned about Sage CRM since Apache is affected. 

    https://github.com/NCSC-NL/log4shell/tree/main/software

    ------------------------------
    Moira Goggin
    Chismet Consulting Corp.
    Long Beach CA
    ------------------------------



  • 13.  RE: Log4J Vulnerability

    Posted 12-16-2021 17:00
    From Sage:

    Important update: Apache Log4j vulnerability

    Dear Partner,

    I want to update you on the Apache Log4j vulnerability that was initially announced on Friday, December 10, 2021, with a subsequent issue being reported on Dec. 15. This is being widely reported as one of the most serious and widespread security vulnerabilities ever discovered-potentially billions of devices and services are at risk. Security and IT teams around the world have spent the last few days attempting to understand and remediate it.

    The very largest companies such as Microsoft, Apple, Cisco, and many others have been impacted (even games such as Minecraft)-there are very few companies unaffected because the Log4j library is so ubiquitous.

    Impact to Sage

    As with all large organizations, the vulnerable Log4j component is present in Sage's technology environments, and teams across the business are working around the clock to mitigate the risk. Good visibility of impacted and potentially impacted services has been achieved, but the investigation continues across all areas.

    Sage is in the process of patching its internal systems. We are continuing to work at pace on Sage product areas that have the potential to be exposed to this vulnerability. As patches become available for Sage products, they will be made available in the usual way through our support sites.

    Updates on Sage products we have patched

    ·     Three online product/services use the vulnerable version of Log4j (Payments Acceptance, Compliance Service and Maxwell Service). All three were protected by tailored web application firewall rules from December 10 and were patched over the weekend-there is no action needed from customers or partners.  

    Sage products with potential vulnerability

    ·     Sage CRM is the only desktop product known to be affected. The manual mitigation published by Apache will eliminate this. Patches have been produced for impacted versions including (2020 R2, 2021 R1, and 2021 R2) and are at the test stage. As soon as the patch is through QA and available to customers, we will issue this through the usual channels.
     

    ·     Sage X3 software is not exposed to the log4j vulnerability; however, Sage X3 integrates natively with a third-party solution called Elasticsearch. Sage X3 versions 11 and 12 are likely to be integrated with impacted instances of Elasticsearch (e.g. version 7.9 and above), but not exposed if our published security best practices have been followed.

    We encourage our customers and partners to review their Elasticsearch installation and follow the security applicable remediation from this provider. Please note that information and guidance on Sage X3 security best practices are available in the Sage X3 online help. Logon to the Sage Partner Hub to view the FAQ

    It's important that we show up for our customers consistently-please see below a holding statement for use when supporting customers or on your customer-facing support sites.

    Best regards

    Nancy Teixeira
    VP Partner Strategy and Sales
    Sage

    Customer support statement

    "Sage and its partners take the security of its customer solutions extremely seriously and regularly undertakes proactive testing across its products to identify potential vulnerabilities and provide fixes. Following the initial announcement of the Apache Log4j vulnerability on December 10, 2021, and subsequent updates, Sage has been investigating the potential impact on our products and services.

    Our initial findings indicate there are no exposed systems in the Sage products or architecture stack that uses log4j. Where we have identified the potential for vulnerability, we have issued an initial patch. We are proactively monitoring the situation and applying and supplying new patches if required.

    However, working with our industry peers and in an abundance of caution, we are upgrading our version of log4j in all areas of our business that use this third-party component.

    If you have further questions, please speak to your account manager in the first instance. We thank you for your patience in this matter."



    ------------------------------
    Brett Zimmerman
    Net at Work
    Greater Boston Area
    ------------------------------



  • 14.  RE: Log4J Vulnerability

    Posted 12-17-2021 11:00

    SAP BusinessObjects BI Platform is not impacted by the CVE-2021-44228.


    Environment

    • SAP BusinessObjects Business Intelligence (BI) Platform 4.2, 4.3 
    • SAP BusinessObjects Business Intelligence (BI) Platform 4.0 / 4.1 * NO LONGER SUPPORTED
    • SAP BusinessObjects Business Intelligence (BI), Edge edition 4.2, 4.3
    • SAP BusinessObjects Business Intelligence (BI), Edge edition 4.0 / 4.1 * NO LONGER SUPPORTED
    • SAP BusinessObjects BI Platform Client Tools 4.2, 4.3
    • SAP BusinessObjects BI Platform Client Tools 4.0, 4.1 * NO LONGER SUPPORTED
    • SAP Crystal Server 2016, 2020
    • SAP Crystal Reports 2016, 2020
    • SAP Crystal Reports for Enterprise 4.2, 4.3
    • BI Platform Support Tool (BIPST)
    • Live Office
    • Universe Design Tool (UDT)
    • Analysis for Office (AO) and Analysis for Office Add-on for BI Platform
    • Lumira Discovery, Lumira Server for BI Platform & Lumira Designer
    • SAP Design Studio * NO LONGER SUPPORTED
    • SAP BI Mobile server
    • All dependent server tools like Upgrade Management Tool, Promotion Management Wizard, Wdeploy
    • All Operating Systems


    ------------------------------
    Gary Feldman
    Cloud Evangelist
    I-Business Network, LLC
    Marietta GA
    http://www.summithosting.com
    ------------------------------



  • 15.  RE: Log4J Vulnerability

    Posted 12-17-2021 11:02
    Sage City Announcement:

    Sage was alerted (Friday 10th December 2021) to a critical remote code execution vulnerability within all Apache log4j versions 2.0-beta9 to 2.15

    References

    https://logging.apache.org/log4j/2.x/security.html

    https://www.ncsc.gov.uk/news/apache-log4j-vulnerability 

    A vulnerability rated with a Critical impact is one which could potentially be exploited by a remote attacker to get Log4j to execute arbitrary code (either as the user the server is running as, or root). These are the sorts of vulnerabilities that could be exploited automatically by worms.

    The Sage 100 Development Team has investigated this, and the Apache Log4J 2 library is NOT used in the supported 2021, 2020, and 2019 versions of Sage 100. The Sage 100 SPC portal and landing page also do not use the Apache Log4J library and are not impacted. 

    For customers using Sage 100 with Sage CRM, Sage CRM have produced patches which are currently being tested and we will advise on results and availability as soon as possible. The Quick Entry Sales Order integration feature does use the Log4J 1 library but the Log4J 1 library is not affected by this vulnerability.  Additionally, customers using Sage Intelligence reporting components of Sage 100 have also been investigated and cleared at this time. Sage Fixed Assets and Sage HRMS have also been cleared.

    Finally, The SAP team has confirmed there is no impact on Crystal Reports, and Aatrix, which we use for payroll e-filing, has published this statement that they are also not impacted (aatrix.com/log4j)

    It is important to note that while Sage has confirmed as many of our integrated applications and services as possible, applications and services provided by independent software vendors may still have vulnerabilities.  Customers should work with their reseller to ensure that their systems are secure.

    References

    https://access.redhat.com/security/cve/cve-2021-44228

    https://solr.apache.org/news.html

    https://launchpad.support.sap.com/#/notes/3129956 

    Please watch the following Sage City links for news: https://www.sagecity.com/us/sage100_erp/f/sage-100-announcements-news-tips



    ------------------------------
    Kevin Moyes
    Technical Systems Analyst
    Munjal White Consulting Co.
    Toronto ON
    ------------------------------



  • 16.  RE: Log4J Vulnerability

    Posted 12-17-2021 16:40
    New issue full article linked

    Recommendation from article:
    Update all local development efforts, internal applications, and internet-facing environments to Log4j 2.16 as soon as possible, before threat actors can weaponize this exploit further. This includes moving any custom applications in their dependency manifests to 2.16 as soon as possible to avoid incidental exploitation. 

    https://www.zdnet.com/article/security-firm-blumira-discovers-major-new-log4j-attack-vector/

    ------------------------------
    Moira Goggin
    Chismet Consulting Corp.
    Long Beach CA
    ------------------------------