SAP Knowledge Base Article - Preview

3768065 - cve-2026-34477 verifyhostname in tls for log4j: impact on wily/introscope (sap extended diagnostics by ca wily)

Symptom

  • Since 10.04.2026, a vulnerability is referenced as CVE-2026-34477 (apache log4j core: verifyHostName attribute silently ignored in tls configuration, allowing hostname verification bypass).
  • Inquiry if the latest service pack includes a fix for CVE-2026-34477.
  • Introscope 10.8 release notes and apm 10.8.0.230 release notes show fixes for cve-2026-44757 and cve-2026-0500, but no mention of cve-2026-34477.
  • Request to confirm whether sp02 (build 10.8.0.230) addresses cve-2026-34477.


Read more...

Environment

  • Product: SAP Extended Diagnostics by CA Wily ;
  • Introscope by CA Technologies

Product

SAP Extended Diagnostics by CA Wily all versions

Keywords

CVE-2026-34477, verifyHostName, TLS, hostname verification bypass, Log4j 2.x, SLF4J, Logback, Wily, Introscope, APM 10.8, SP02 10.8.0.230, vulnerability, security, not affected, NetWeaver AS Java , KBA , XX-PART-WILY , Introscope by CA Technologies , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.