Symptom
- Since 10.04.2026, a vulnerability is referenced as CVE-2026-34477 (apache log4j core: verifyHostName attribute silently ignored in tls configuration, allowing hostname verification bypass).
- Inquiry if the latest service pack includes a fix for CVE-2026-34477.
- Introscope 10.8 release notes and apm 10.8.0.230 release notes show fixes for cve-2026-44757 and cve-2026-0500, but no mention of cve-2026-34477.
- Request to confirm whether sp02 (build 10.8.0.230) addresses cve-2026-34477.
Read more...
Environment
- Product: SAP Extended Diagnostics by CA Wily ;
- Introscope by CA Technologies
Product
SAP Extended Diagnostics by CA Wily all versions
Keywords
CVE-2026-34477, verifyHostName, TLS, hostname verification bypass, Log4j 2.x, SLF4J, Logback, Wily, Introscope, APM 10.8, SP02 10.8.0.230, vulnerability, security, not affected, NetWeaver AS Java , KBA , XX-PART-WILY , Introscope by CA Technologies , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview