We are getting lot of vulnerabilities during scans because of log4j and planning to upgrade to log4j2 latest version, can someone suggest how can plan our upgrade activity.
If possible please confirm what all files/jars needs to be updated.
hopefully you have support contracts with SAG (Extended for 10.3) in place.
SAG has released Fixes for this third party component to remediate these vulnerabilities already.
For 10.3 this should be at least TPP_10.3_log4J_Fix2, which updates to log4j 1.2.18.3.
For 10.11 this should be at least TPP_10.11_Loggers_Fix1 and TPS_10.11_Loggers_Fix1, which updates to log4j 2.16.0.
You should consider upgrading both versions to wM 10.15 as soon as possible.
I suggest upgrading the webMethods version instead of just updating log4j. There are probably a lot more vulnerabilities since that version stopped receiving updates.