Share all details about your problem, including any error messages you may have received.
Is there official remediation for CVE-2026-34477 in SailPoint IdentityIQ 8.3p3 and whether Log4j 2.25.4 can be deployed as a direct library replacement, or whether an IdentityIQ patch or hotfix is required.
“The fix for CVE-2025-68161 Security :: Apache Logging Services was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName”
CVE-2026-34477 (SSL Hostname Verification Bypass / MitM) — This CVE relates to the possibility of a man-in-the-middle attack that could intercept log data when Log4j is configured to send logs over the network. In the default configuration of Log4j in IdentityIQ, all logging stays on the local filesystem and network appenders are not configured or used. In that setup, this CVE does not apply. The issue would only be relevant if the Log4j configuration in your IdentityIQ deployment was changed to use network-based appenders. IdentityIQ is not impacted by this vulnerability in its default configuration.
Log4j is updated to version 2.25.3 in IdentityIQ 8.4p4. Log4j will be updated to version 2.25.4 in IdentityIQ 8.4p5, 8.5p2, and 9.0.