PVCS Version Manager is not affected by these vulnerabilities in log4j 1.2.17, despite what a vulnerability scanner might say. CVE -2019-17571 Exploiting this issue requires a configuration using the SocketServer to listen for network traffic, which is not being used by PVCS Version Manager.
. SBM is not vulnerable to recorded CVEs, but we recognize the concern with having the "unsupported" version of log4j 1.2.xx on the server. We will replace this component in the October 2022 release of SBM.