Hi Carl
Just to come back to something you said at the beginning ...
The client is currently using Genero 2.41 which has a file in Report Writer called log4j-1.2.13.jar.
The client may be happy that the log4j is outside the version range that contains the vulnerability. But what if the client requires an update to the log4j 2.15.0 version that has been patched?
As the current supported versions are Genero 4.00, 3.20, 3.10 as per our current plus two previous strategy, if hypothetically your client had required an update, they may have found that we only delivered maintenance releases for 3.10, 3.20 and 4.00. If you look at Oliviers announcement
https://forum.4js.com/fjs_forum/index.php?topic=1735.0 he references the three supported versions, if you look at the download products and download documentation page of our website, you will see the three supported versions.
Fortunately it has not happened in this instance but by continuing to use old versions you do face the possibility that an event such as this occurs, and you are left with the prospect of upgrading to a supported version of Genero at short notice.
Reuben