I have applied the fix for log4j patch to Cisco Unified Call Studio 12.6, but our security team still complained below war/jar files. Is there another patch to fix? thanks!
The vulnerable instances are located at...
...\CallStudio12.6\eclipse\plugins\com.audiumcorp.studio.debug.runtime\lib\CVP.war
...\CallStudio12.6\eclipse\plugins\com.audiumcorp.studio.library.common\lib\log4j-core.jar
...\CallStudio12.6\eclipse\plugins\com.audiumcorp.studio.library.framework\lib\log4j-core.jar
...\CallStudio12.6\eclipse\plugins\com.audiumcorp.studio.builder.documenter\lib\log4j-core.jar
...\CallStudio12.6\eclipse\plugins\com.audiumcorp.studio.extensionkit.core\lib\log4j-core.jar
...\CallStudio12.6\eclipse\plugins\com.audiumcorp.studio.debug.runtime\CATALINA_HOME\webapps\CVP\WEB-INF\lib\log4j-core.jar
...\CallStudio12.6\eclipse\plugins\com.audiumcorp.studio.debug.core\lib\log4j-core.jar