Advisory: Apache log4j vulnerability (CVE-2021-45046)

Sage was alerted (Tuesday 14th December 2021) to a Common Vulnerabilities and Exposures notice (CVE-2021-45046) that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations.

Note that a previous mitigation involving configuration to set the system property log4j2.noFormatMsgLookup to true does NOT mitigate this specific vulnerability. Please see the Apache site for more details.


The Apache Log4J 2 library is used in the 2020 R2, 2021 R1, and 2021 R2 versions of Sage CRM.

Patches for Sage CRM
Sage has 3 patches in test to update Apache Log4j to 2.16

Sage CRM 2020 R2
Sage CRM 2021 R1
Sage CRM 2021 R2

Availability of the patches will be announced on Sage City.

Please watch the following Sage City links for news:

This applies for Sage CRM stand-alone and when integrated with Sage accounting products. Sage 50, Sage 100, Sage 200, Sage 1000, Sage 300, Sage X3 and Sage Intacct.