Currently the log4j installed version is : 2.17.1, it is advised to upgrade the version of log4j to 2.25.4.
CA Service Desk 17.4 RU5
CA Service Desk only uses PatternLayout of log4j2 and hence it is not affected by this vulnerability.
The vulnerability stems from undocumented and silent configuration attribute renames within the Rfc5424Layout component of Apache Log4j2.