Improper Certificate Validation in Apache Log4j - CVE-2026-34477

 

Improper Certificate Validation in Apache Log4j - CVE-2026-34477

Published: April 28, 2026


Vulnerability identifier: #VU128399
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34477
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a man-in-the-middle attack.

The vulnerability exists due to improper certificate validation in the TLS hostname verification handling of the verifyHostName attribute in Log4j Core SSL configuration when establishing TLS connections for SMTP, Socket, or Syslog appenders. A remote attacker can present a certificate issued by a trusted certificate authority to perform a man-in-the-middle attack.

The issue occurs only when TLS is configured via a nested SSL configuration element, and it does not affect the HTTP appender.


Affected software

Apache Log4j
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Db2 Developer Extension
PowerVM NovaLink
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Virtual Environments: Data Protection for VMware
Integration Bus for z/OS
webMethods BPM
ApplinX
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Maximo Scheduler Optimizer
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Sterling Connect:Direct Web Services
Netcool/OMNIbus
IBM Tivoli Netcool/OMNIbus WebGUI
IBM SPSS Collaboration and Deployment Services
IBM SPSS Modeler
IBM Decision Optimization for Cloud Pak for Data
IBM License Metric Tool
IBM DB2
IBM InfoSphere Information Server
IBM App Connect Enterprise
IBM Disconnected Log Collector
log4j-javadoc
log4j-jcl
log4j-slf4j
log4j

How to mitigate CVE-2026-34477

Install security update from vendor's website.

Apache Log4j - update to 2.25.4
Db2 Developer Extension - update to 1.1.2
PowerVM NovaLink - addressed in versions 2.2.1.1, 2.3.3
IBM Security Guardium Key Lifecycle Manager (GKLM) - addressed in versions 5.0.0 FP3, 5.1.0 FP2
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
Netcool/OMNIbus - update to 8.1.0.37
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.41
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.2.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.2.0
IBM License Metric Tool - update to 9.2.44
webMethods BPM - addressed in versions 10.15 Fix 2, 11.1 Fix 2, 12.1 Fix 1
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
IBM App Connect Enterprise - addressed in versions 12.0.12.26, 13.0.7.2
IBM Disconnected Log Collector - update to 2.0.1
log4j-javadoc - update to 2.20.0-150200.4.33.1
log4j-jcl - update to 2.20.0-150200.4.33.1
log4j-slf4j - update to 2.20.0-150200.4.33.1
log4j - update to 2.20.0-150200.4.33.1
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 6
watsonx Assistant Cartridge - update to 5.4
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.4
Maximo Scheduler Optimizer - addressed in versions 9.0.25, 9.1.14, 9.2.1

External References

Related Security Bulletins