CVE-2026-34477 and CA Service Desk Manager
search cancel

CVE-2026-34477 and CA Service Desk Manager

book

Article ID: 443118

calendar_today

Updated On:

Products

CA Service Management - Service Desk Manager CA Service Desk Manager

Issue/Introduction

Customers may inquire whether CA Service Desk Manager are affected by the Log4j vulnerability identified as CVE-2026-34477 (Man-in-the-Middle/Broken TLS Hostname Verification).

 

Environment

CA Service Desk Manager (SDM) 17.3.x and 17.4.x
Vulnerability: CVE-2026-34477

Cause

CVE-2026-34477 involves a potential man-in-the-middle attack when an SMTP, Socket, or Syslog appender is in use with TLS configured via a nested element. If the attacker can present a trusted certificate, they may exploit broken hostname verification.

Resolution

Broadcom Service Management Engineering has confirmed that CA Service Desk Manager is NOT affected by this vulnerability.

Technical Justification

  • The vulnerability specifically affects users of SMTP, Socket, or Syslog appenders
  • CA Service Desk Manager and its components exclusively use the `RollingFileAppender` for logging
  • Because the vulnerable appenders are not utilized, the attack vector described in CVE-2026-34477 is not present in the product

Additional Information

Note: This vulnerability does not affect users of the HTTP appender, which uses a separate `verifyHostname` logic.

See also: Process Automation (ITPAM) Not Affected by Log4j CVE-2026-34477