Kurve does not bundle Log4j. It was included in older TjeneConnect builds and has since been removed. Current Kurve releases do not include it.
If a security scan flags Log4j in your environment, the files are most likely leftover from a previous install that remained in the TRIRIGA Class Loader after an upgrade. Kurve does not use them as an active component.
To remove these traces:
- Open TRIRIGA.
- Go to Tools > System Setup > System.
- Select Class Loader, then click TjeneConnectV3.
- In the resource file list, delete any entries containing "log4j" (log4j, log4j-api, log4j-core).
Removing these files does not affect Kurve functionality. Re-run the security scan. The Log4j finding should no longer appear.
Still seeing the issue? Submit a ticket.