A number of vulnerabilities have been published for Apache Log4J version 2 impacting Log4j2 2.0-beta9 through to 2.25.3
Siteminder bundles Apache Log4J2 in a number of components, including Siteminder Web Agents
Log4J by Siteminder Web Agent Version:
r12.52.1: Log4j 1.2.8
r12.8: Log4j 2.17.2
Log4j 2.25.3 was delivered in a series of component specific KB's.
This KB will allow you to upgrade Log4J on the Siteminder Web Agents in the APS.war file to Log4J 2.25.4
NOTE: For Siteminder Application Server Agents (ASA) for WebLogic and WebLogic See 438214 Vulnerability in Log4j 2.25.3 And Older on Siteminder Application Server Agents (ASA)
PRODUCT: Siteminder
COMPONENT: Web Agents
VERSION: 12.52.x; 12.8
OPERATING SYSTEM: Any
The following CVE has been published for log4J impacting all versions of Log4J 2.25.3 and older.
CVE-2026-34481 "Improper serialization of non-finite floating-point values in JsonTemplateLayout"
IMPACT: Medium
DESCRIPTION: Apache Log4j’s JsonTemplateLayout, in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. This may cause downstream log processing systems to reject or fail to index affected records.
IMPACTED: Log4J 2.25.3 and older
REMDIATED: Log4J 2.25.4
CVE-2026-34480 "Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters"
IMPACT: Medium
DESCRIPTION: Apache Log4j Core’s XmlLayout, in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification producing invalid XML output whenever a log message or MDC value contains such characters.
IMPACTED: Log4J 2.25.3 and older
REMDIATED: Log4J 2.25.4
CVE-2026-34479 "Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters"
IMPACT: Medium
DESCRIPTION: The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.
IMPACTED: Log4J 2.25.3 and older
REMDIATED: Log4J 2.25.4
CVE-2026-34478 "Log injection in Rfc5424Layout due to silent configuration incompatibility"
IMPACT: Medium
DESCRIPTION: Apache Log4j Core’s Rfc5424Layout, in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes.
IMPACTED: Log4J 2.25.3 and older
REMDIATED: Log4J 2.25.4
CVE-2026-34477 "verifyHostName attribute silently ignored in TLS configuration"
IMPACT: Medium
DESCRIPTION: The fix for CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName system property, but not when configured through the verifyHostName attribute of the <Ssl> element.
IMPACTED: Log4J 2.25.3 and older
REMDIATED: Log4J 2.25.4
Update the APS.war file on the Siteminder Web Agent.
Attached to this KB is an updated 'APS.war' file which contains Log4J 2.25.4.
1) Logon to the Web Agent Server
2) Stop the Web Server
3) Browse to the following directory:
LINUX: <Install_Dir>/webagent/bin/Web/APS.war
WINDOWS: <Install_Dir>\CA\webagent\win64\bin\Web\APS.war
4) Backup/Rename the existing 'APS.war' file
5) Copy the 'APS.war' file from this KB into the directory where the original 'APS.war' was located.
6) Start the Web Agent and validate functionality
7) Once Web Agent functionality is confirmed, delete the backed-up version of the 'APS.war' file.
438214 Vulnerability in Log4j 2.25.3 And Older on Siteminder Application Server Agents (ASA)
438213 Vulnerability in Log4j 2.25.3 And Older on Siteminder SDK
438210 Vulnerability in Log4j 2.25.3 And Older on Siteminder AdminUI
438208 Vulnerability in Log4j 2.25.3 and Older on Siteminder Access Gateway
438204 Vulnerability in Log4j 2.25.3 And Older on the Siteminder Policy Server
Apache.org Vulnerabilities in Logging Services
Log4J2.25.4 remediates the following CVE's
CVE-2026-34481
CVE-2026-34480
CVE-2026-34479
CVE-2026-34478
CVE-2026-34477
CVE-2025-68161
CVE-2021-44228
CVE-2021-45046
CVE-2021-45105
CVE-2021-44832
CVE-2021-4104