Apache Log4j 2.12.0 < 2.25.4 SSL Hostname Verification Bypass (CVE-2026-34477)

Which IIQ version are you inquiring about?

8.4p3

Please share any other relevant files that may be required (for example, logs).

Apache Log4j 2.12.0 < 2.25.4 SSL Hostname Verification Bypass (CVE-2026-34477)

Share all details about your problem, including any error messages you may have received.

Is there official remediation for CVE-2026-34477 in SailPoint IdentityIQ 8.3p3 and whether Log4j 2.25.4 can be deployed as a direct library replacement, or whether an IdentityIQ patch or hotfix is required.

@fghafour Based on NIST site, solution is not completed yet: NVD - CVE-2026-34477

“The fix for CVE-2025-68161 Security :: Apache Logging Services was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName”

You can refer to this.

CVE-2026-34477: Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass-Apache Mail Archives

NVD - CVE-2026-34477

Anyone applied the fix in any version of Sailpoint IIQ? As the fix is to Upgrade to Apache Log4j version 2.25.4 or later.

CVE-2026-34477 (SSL Hostname Verification Bypass / MitM) — This CVE relates to the possibility of a man-in-the-middle attack that could intercept log data when Log4j is configured to send logs over the network. In the default configuration of Log4j in IdentityIQ, all logging stays on the local filesystem and network appenders are not configured or used. In that setup, this CVE does not apply. The issue would only be relevant if the Log4j configuration in your IdentityIQ deployment was changed to use network-based appenders. IdentityIQ is not impacted by this vulnerability in its default configuration.

Log4j is updated to version 2.25.3 in IdentityIQ 8.4p4. Log4j will be updated to version 2.25.4 in IdentityIQ 8.4p5, 8.5p2, and 9.0.