A security vulnerability (CVE-2026-49844) involving improper JSON serialization was identified in the Log4j 2.25.4 libraries included with CA Identity Manager. This article provides the hotfix to upgrade the libraries to Log4j 2.26.1.
A product defect in version 14.5 CP1 utilizes a version of Log4j (2.25.4) that is susceptible to CVE-2026-49844.
A hotfix is available to upgrade the affected libraries to Log4j version 2.26.1.