Apache log4j vulnerability details with path detection found in Discovery agent probe:
Number | Summary | ID |
| VIT165971886 | Apache Log4j Core: CVE-2026-34477: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass | R7-apache-log4j-core-cve-2026-34477 |
| VIT165972227 | Apache Log4j Core: CVE-2026-34477: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass | R7-apache-log4j-core-cve-2026-34477 |
Path detection: ...\Nimsoft\probes\service\discovery_agent\lib\log4j-1.2-api-2.20.0.jar
CVE-2026-34477 is resolved in log4j-2.25.4 and 23.4 CU8 is already using log4j-2.25.4.
All probes including the discovery_agent are using log4j-2.25.4. All of the UIM probes are using log4j-2.25.4 in CU8.
The mentioned vulnerability is not present in the discovery_agent probe version 23.4.8.
CVE-2026-34477 is resolved in log4j-2.25.4 and 23.4 CU8 is already using log4j-2.25.4 so all the probes including the discovery_agent are using log4j-2.25.4.
We highly recommend upgrading the UIM environment to CU8.