Security scans may return a report that they have found multiple JAVA vulnerabilities on servers running SEPM and LUA with the below packages :
Jackson (Databind / Core)
YAML / JWT Parsing
Apache Shiro
Jetty (bundled inside a third-party tool only)
Logback
Apache Commons / Connection Pooling
SEPM
LUA
LUA is not vulnerable to any of the reported CVEs because no management, JMX, or REST configuration is used.