Question

og4j security vulnerability with SAP Crystal Reports for .NET SDK

  • 11 January 2022
  • 6 replies
  • 561 views

Userlevel 3
Badge +6

Hi Community, 

We were just made aware of a severe vulnerability in the Java logging library Apache Log4j.

See the following article for more information:

https://www.zdnet.com/article/security-warning-new-zero-day-in-the-log4j-java-library-is-already-being-exploited

 

Please note that we are using IFS Apps 9 and if Apps 9 supports latest version of Crystal Reports runtime?

 

The latest version of Crystal Reports runtime has removed this vulnerability. 

 

Best Regards

Asanga 


6 replies

Userlevel 7
Badge +15

Hi,

 

As Crystal Reports for .NET runtime SDK is a 3rd party library, it’s hard for us to give an exact answer.

Please refer the SAP Crystal community forum post given below for more details.

https://answers.sap.com/questions/13545419/log4j-security-vulnerability-with-sap-crystal-repo.html

 

Regards,

Chanaka

Userlevel 3
Badge +6

Hi, 

 

If you read my question I need to know does the latest Crystal Runtime supports IFS Apps 9?

 

Best Regards

Asanga

Userlevel 7
Badge +15

Hi,

The Crystal Report .Net runtime that we have tested with and compatible with the the Crystal Web Service is packed with the Crystal Web Service installation zip. Installing a version other than that might cause the Crystal Web Service to stop working as expected or might give errors. Therefore it’s recommended to use the Crystal Report .Net runtime in the installation zip.

Regards,

Chanaka

Userlevel 3
Badge +6

Do you know if IFS is using Apache Log4j for printing?

Userlevel 7
Badge +15

Hi,

 

IFS Report Designer framework doesn’t use it. 

The jar file is there in IFS Web Client. This again IFS doesn’t use it. It’s a dependent jar for the Crystal Java SDK jars used to preview Crystal Quick Reports in IFS Web Client. The Log4j jar there also is not affected with the particular vulnerability you have mentioned  above in this post as it’s not  Log4j 2.x.

 

Regards,

Chanaka

Userlevel 5
Badge +10

IFS Analyzed all released code for the Log4j (CVE-2021-44228) vulnerability.
A few weeks back IFS has stated that IFS Apps9 is not affected by the Log4j vulnerability - and that includes Crystal Web Service.

Reply