Apache log4j vulnerability CVE-2026-34477 found in scan for discovery_agent in DX UIM 23.4 CU2
search cancel

Apache log4j vulnerability CVE-2026-34477 found in scan for discovery_agent in DX UIM 23.4 CU2

book

Article ID: 451930

calendar_today

Updated On:

Products

DX Unified Infrastructure Management (Nimsoft / UIM) CA Unified Infrastructure Management On-Premise (Nimsoft / UIM) CA Unified Infrastructure Management SaaS (Nimsoft / UIM)

Issue/Introduction

Apache log4j vulnerability details with path detection found in Discovery agent probe:

Number

SummaryID
VIT165971886Apache Log4j Core: CVE-2026-34477: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypassR7-apache-log4j-core-cve-2026-34477
VIT165972227Apache Log4j Core: CVE-2026-34477: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypassR7-apache-log4j-core-cve-2026-34477

 

Path detection: ...\Nimsoft\probes\service\discovery_agent\lib\log4j-1.2-api-2.20.0.jar

Environment

  • DX UIM 23.4 CU2

Cause

  • Medium Security vulnerability found during scan

Resolution

  • CVE-2026-34477 is resolved in log4j-2.25.4 and 23.4 CU8 is already using log4j-2.25.4.

  • All probes including the discovery_agent are using log4j-2.25.4. All of the UIM probes are using log4j-2.25.4 in CU8.

  • The mentioned vulnerability is not present in the discovery_agent probe version 23.4.8.

    • CVE-2026-34477 is resolved in log4j-2.25.4 and 23.4 CU8 is already using log4j-2.25.4 so all the probes including the discovery_agent are using log4j-2.25.4.

  • We highly recommend upgrading the UIM environment to CU8.