We have CA Configuration Automation 12.9.
Our security found these three vulnerabilities and all of them are said to be fixed by Apache Log4j version 2.25.4 or later
CA Configuration Automation 12.9/12.9 CU1
Please upgrade to 12.9 CU2, which has Apache Log4j version 2.25.4, to address these vulnerbilities
Release Announcement for Configuration Automation 12.9 CU2