Log4j 2.25.4 Hotfixes for CA Identity Suite (14.5.1 CHF2)
search cancel

Log4j 2.25.4 Hotfixes for CA Identity Suite (14.5.1 CHF2)

book

Article ID: 443919

calendar_today

Updated On:

Products

CA Identity Suite CA Identity Governance CA Identity Manager CA Identity Portal

Issue/Introduction

Security scans indicate that Identity Manager and Governance (IGA components) are impacted by a Log4j vulnerability (CVE-2026-34477).

Environment

  • Products: Identity Manager, Identity Governance, Identity Portal, Virtual Appliance
  • Version: 14.5.1 CHF2
  • Installed Log4j: 2.25.3
  • Required Log4j: 2.25.4

Cause

The vulnerability was identified in the Log4j 2.25.3 library utilized by various IGA components.

Resolution

Engineering has released specific hotfixes to update Log4j to version 2.25.4. These patches should be applied on top of the 14.5.1 CHF2 release.

Download Links

Refer to the following release note pages for the relevant hotfix downloads: