Apache Log4j vulnerability CVE-2026-49844
search cancel

Apache Log4j vulnerability CVE-2026-49844

book

Article ID: 452576

calendar_today

Updated On:

Products

DX Unified Infrastructure Management (Nimsoft / UIM)

Issue/Introduction

This article addresses security vulnerability CVE-2026-49844 identified in DX UIM 23.4 CU8 and earlier versions, caused by improper JSON serialization in Apache Log4j

Environment

DX UIM 23.4 (all CU levels prior to CU9)

Resolution

This issue is targeted to be fixed in UIM 23.4 CU9 (planned release mid-September 2026). All Log4j components will be upgraded to the latest non-vulnerable version 2.26.1 in this release. Please subscribe to this article for further updates.

Additional Information

For steps to download releases, visit Download Broadcom products and software. To contact support for additional queries, see Contact Broadcom Support.