medium2026-09-08SAP Commerce Cloud — Search and NavigationCVE-2026-34477
Apache Log4j Configuration Vulnerability in Commerce Cloud
SAP Commerce Cloud
Our Take
Commerce Cloud has two notes this month — this and the Jetty CRLF (3791068). They share the same module so a single deployment cycle can address both. This is a Log4j configuration issue rather than Log4Shell, but Log4j misconfigurations remain a meaningful attack surface.
Vulnerability Detail
Apache Log4j configuration vulnerability in the SAP Commerce Cloud Search and Navigation component. Distinct from the Jetty CRLF issue in the same module (Note 3791068).
Patch Action
Apply SAP Note 3787345 to update the Log4j configuration in the Search and Navigation component.
Patch Info