Security scans indicate that Identity Manager and Governance (IGA components) are impacted by a Log4j vulnerability (CVE-2026-34477).
The vulnerability was identified in the Log4j 2.25.3 library utilized by various IGA components.
Engineering has released specific hotfixes to update Log4j to version 2.25.4. These patches should be applied on top of the 14.5.1 CHF2 release.
Refer to the following release note pages for the relevant hotfix downloads: