Kurve does not bundle Log4j. It was included in older TjeneConnect builds and has since been removed. Current Kurve releases do not include it.


If a security scan flags Log4j in your environment, the files are most likely leftover from a previous install that remained in the TRIRIGA Class Loader after an upgrade. Kurve does not use them as an active component.


To remove these traces:

  1. Open TRIRIGA.
  2. Go to Tools > System Setup > System.
  3. Select Class Loader, then click TjeneConnectV3.
  4. In the resource file list, delete any entries containing "log4j" (log4j, log4j-api, log4j-core).

Removing these files does not affect Kurve functionality. Re-run the security scan. The Log4j finding should no longer appear.


Still seeing the issue? Submit a ticket.