Symantec DLP and CVE-2026-34477 Vulnerability Assessment
search cancel

Symantec DLP and CVE-2026-34477 Vulnerability Assessment

book

Article ID: 447069

calendar_today

Updated On:

Products

Data Loss Prevention Enforce Data Loss Prevention

Issue/Introduction

Customers may report a vulnerability scan identifying CVE-2026-34477 associated with log4j-to-slf4j-2.17.2.jar in the following Symantec Data Loss Prevention (DLP) Enforce Server paths:

  • \Program Files\Symantec\DataLossPrevention\EnforceServer\25.1.00000\Protect\lib\jar\log4j-to-slf4j-2.17.2.jar
  • \Program Files\Symantec\DataLossPrevention\EnforceServer\25.1.00000\Protect\tomcat\webapps\ProtectManager\WEB-INF\lib\log4j-to-slf4j-2.17.2.jar

Note: The paths may differ based on the target directory selected during installation of the product.

Environment

Symantec Data Loss Prevention (DLP) Enforce Server

Version 25.1 and potentially others with the impacted JAR library deployed as a part of the Tomcat installation.

Cause

The log4j-to-slf4j library is included as part of the Apache Tomcat installation bundled with the DLP Enforce Server.

Resolution

Symantec DLP is not vulnerable to CVE-2026-34477.

While the Log4j library is present within the Tomcat directory structure, Symantec DLP does not utilize Log4j in any of its application code. Because the library is not used by the product, DLP is not impacted by this Log4j-related vulnerability.