Catalyst 184.108.40.206 contains several appearances of log4j.jar files which appear to be version 1.2.17. The customers security scanner marks this as potentially vulnerable. Are there plans to substitute this with 2.17.1 or higher and are there instructions available how to remove the vulnerable components from this files.
Release : 4.2
Component : SOI INSTALL