Customers may inquire whether CA Service Desk Manager are affected by the Log4j vulnerability identified as CVE-2026-34477 (Man-in-the-Middle/Broken TLS Hostname Verification).
CA Service Desk Manager (SDM) 17.3.x and 17.4.x
Vulnerability: CVE-2026-34477
CVE-2026-34477 involves a potential man-in-the-middle attack when an SMTP, Socket, or Syslog appender is in use with TLS configured via a nested element. If the attacker can present a trusted certificate, they may exploit broken hostname verification.
Broadcom Service Management Engineering has confirmed that CA Service Desk Manager is NOT affected by this vulnerability.
Technical Justification
Note: This vulnerability does not affect users of the HTTP appender, which uses a separate `verifyHostname` logic.
See also: Process Automation (ITPAM) Not Affected by Log4j CVE-2026-34477