A patch to resolve this issue (by replacing the affected files with log 4 j 2 .17.1) is now available for PVCS Version Manager 8.6.3. The VM 8.6.3.2 patch is available from the product download pages
CVE 2021-44228: A serious security issue affecting SBM, RCE 0-day exploit, has been found for log 4 j 2 .0 – 2.14.1. For further information on the vulnerability, you can follow the Apache Log4j site .
ALM Solution Connector 6.2.5 has been released and includes Log 4 j version 2.17.1 . The release can be downloaded from the SLD Download Center . Be sure to install the new Micro Focus Common Tomcat and not just the war files.