Vulnerability scan flags Log4j in Fast Data Masker (FDM) after TDM 4.11 upgrade (CVE-2026-34480, CVE-2026-34478, CVE-2026-34477)
search cancel

Vulnerability scan flags Log4j in Fast Data Masker (FDM) after TDM 4.11 upgrade (CVE-2026-34480, CVE-2026-34478, CVE-2026-34477)

book

Article ID: 446422

calendar_today

Updated On:

Products

CA Test Data Manager (Data Finder / Grid Tools)

Issue/Introduction

After upgrading all Test Data Manager components to version 4.11, vulnerability scanners (such as Tenable.io) continue to report Apache Log4j vulnerabilities associated with the Fast Data Masker component.

The findings typically point to the following path: C:\Program Files\Grid-Tools\FastDataMasker\FDMServlet.jar

Reported CVEs:

  • CVE-2026-34480: XmlLayout fails to sanitize forbidden characters, producing invalid XML output.
  • CVE-2026-34478: Rfc5424Layout is vulnerable to log injection via CRLF sequences.
  • CVE-2026-34477: SSL Hostname Verification Bypass due to ignored verifyHostName attribute.

Environment

Product: Test Data Manager (TDM) Component: Fast Data Masker (FDM) Release: 4.11.x

Cause

The base release of TDM 4.11 does not contain the specific Log4j version (2.25.4 or newer) required to remediate these specific CVEs within the FDMServlet.jar file used by Fast Data Masker.

Resolution

Broadcom Engineering has released a specific patch for Fast Data Masker to address these vulnerabilities by updating the internal Log4j libraries.

To resolve the issue:

  1. Download Patch: Obtain the FastDataMasker-5.0.18.0 patch (or the latest available FDM 5.x patch compatible with your environment).
  2. Apply Patch: Replace the existing FDMServlet.jar and associated libraries in the FDM installation directory with the versions provided in the patch.
  3. Verify Compatibility: While FDM build 5.0.18.0 is compatible with TDM Portal version 4.11.5045, it is highly recommended to upgrade the TDM Portal to the latest 5.x build to maintain full version alignment and security compliance.
  4. Validate: Rerun the vulnerability scan to confirm the findings for the FDM path are cleared.

Download Location: Patches can be found on the Test Data Manager (TDM) Patches page.