This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Advisory: Apache log4j vulnerability (CVE-2021-44228)

Sage was alerted (Friday 10th December 2021) to a critical remote code execution vulnerability within all Apache log4j versions 2.0-beta9 to 2.15


A vulnerability rated with a Critical impact is one which could potentially be exploited by a remote attacker to get Log4j to execute arbitrary code (either as the user the server is running as, or root). These are the sorts of vulnerabilities that could be exploited automatically by worms.

The Sage 100 Development Team has investigated this, and the Apache Log4J 2 library is NOT used in the supported 2021, 2020, and 2019 versions of Sage 100. The Sage 100 SPC portal and landing page also do not use the Apache Log4J library and are not impacted. 

For customers using Sage 100 with Sage CRM, Sage CRM have produced patches which are currently being tested and we will advise on availability as soon as possible. The Quick Entry Sales Order integration feature does use the Log4J 1 library but the Log4J 1 library is not affected by this vulnerability.  Additionally, customers using Sage Intelligence reporting components of Sage 100 have also been investigated and cleared at this time. Sage Fixed Assets and Sage HRMS have also been cleared.

Finally, The SAP team has confirmed there is no impact on Crystal Reports, and Aatrix, which we use for payroll e-filing, has published this statement that they are also not impacted (

It is important to note that while Sage has confirmed as many of our integrated applications and services as possible, applications and services provided by independent software vendors may still have vulnerabilities.  Customers should work with their reseller to ensure that their systems are secure.


Please watch the following Sage City links for news: