Is CA SDM impacted by CVE-2026-34478 - LOG4J VULNERABILITY?
search cancel

Is CA SDM impacted by CVE-2026-34478 - LOG4J VULNERABILITY?

book

Article ID: 442477

calendar_today

Updated On:

Products

CA Service Desk Manager

Issue/Introduction

Need to know if CA SDM is affected by CVE-2026-34478 - LOG4J VULNERABILITY (CRLF / LOG INJECTION).

Currently the log4j installed version is : 2.17.1, it is advised to upgrade the version of log4j to 2.25.4.

Environment

CA Service Desk 17.4 RU5

Resolution

CA Service Desk only uses PatternLayout of log4j2 and hence it is not affected by this vulnerability.

The vulnerability stems from undocumented and silent configuration attribute renames within the Rfc5424Layout component of Apache Log4j2.