Log4j 2.25.4 Vulnerability CVE-2026-49844 in Identity Manager 14.5 CP1
search cancel

Log4j 2.25.4 Vulnerability CVE-2026-49844 in Identity Manager 14.5 CP1

book

Article ID: 453020

calendar_today

Updated On:

Products

CA Identity Manager

Issue/Introduction

A security vulnerability (CVE-2026-49844) involving improper JSON serialization was identified in the Log4j 2.25.4 libraries included with CA Identity Manager. This article provides the hotfix to upgrade the libraries to Log4j 2.26.1.

Environment

  • CA Identity Manager 14.5 CP1
  • CA Identity Suite (Virtual Appliance, Identity Portal, Identity Governance)
  • Log4j version 2.25.4

Cause

A product defect in version 14.5 CP1 utilizes a version of Log4j (2.25.4) that is susceptible to CVE-2026-49844.

Resolution

A hotfix is available to upgrade the affected libraries to Log4j version 2.26.1.

  1. Install 14.5.1 CHF2 as a mandatory prerequisite.
  2. Download the appropriate hotfix for your component from the Symantec Security Software TechDocs:
  3. Apply the hotfix following the instructions provided in the release notes for your specific environment.