medium2026-09-08SAP Commerce Cloud — Search and NavigationCVE-2026-34477

Apache Log4j Configuration Vulnerability in Commerce Cloud

SAP Commerce Cloud

Our Take

Commerce Cloud has two notes this month — this and the Jetty CRLF (3791068). They share the same module so a single deployment cycle can address both. This is a Log4j configuration issue rather than Log4Shell, but Log4j misconfigurations remain a meaningful attack surface.

Vulnerability Detail

Apache Log4j configuration vulnerability in the SAP Commerce Cloud Search and Navigation component. Distinct from the Jetty CRLF issue in the same module (Note 3791068).

Patch Action

Apply SAP Note 3787345 to update the Log4j configuration in the Search and Navigation component.

Patch Info

CVSS Score

5.9

SAP Note

3787345

CVE

CVE-2026-34477

Published

2026-09-08

← All patches