This article clarifies whether Symantec Identity Manager is exposed to the Log4j v1.2x vulnerability identified as CVE-2021-44832 (JDBCAppender Vulnerability).
Identity Manager
Sustaining Engineering has investigated this vulnerability and determined that Symantec Identity Manager is not vulnerable to CVE-2021-44832 by default.
If you have manually declared the JDBCAppender in your Log4j configuration, you must take the following steps to secure the environment:
JDBCAppender references in your Log4j configuration files.JDBCAppender configuration entirely if it is not required for your deployment.