Log4shell or Log4j2 or more simply CVE-2021-44228 is being called the greatest vulnerability to hit the interest... ever. Log4j2 impact touches anything that uses Apache’s opensource logging service Log4j prior to version 2.15.0. And that’s a lot of systems. In fact, it’s said to impact most of the web services attached to the Internet at the time of the exploit’s announcement on December 9th, 2021. That’s a lot of systems to patch. How does a cyber team work through all of the known and shadow IT inventory? Further, what if those systems are the heart of the company running critical financial and management functions, such as a SAP or other ERP system? Patching of these systems must be prioritized, but it will take time. More immediately, cyber teams should be looking to their security partners to implement network-wide mitigation that can be broadly and swiftly deployed. Fortinet has rolled out several countermeasures to stop 44228 right now. This approach, which you can think of as virtual patching, will protect your systems while buying time for system admins and vendors to roll out application-specific patches.
Protecting SAP and other ERP systems must be a high priority. SAP has published a bulletin as of December 14th, 2021 of the impacted products which can be found here. However, patching and validating those systems is not a trivial task.
Fortinet can help mitigate the impact of log4shell across the SAP landscape in the following ways:
Fortinet is the only network and application security provider able to provide secure the entire SAP landscape. Fortinet has built connectors allowing the Fortinet security fabric to changes in the SAP landscape. We have also incorporated SAP-specific threat detections for our solutions.
To learn more about Fortinet’s SAP portfolio, visit https://fortinet.com/sap.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.