Skip to main content
Solved

Rocket MV Basic - Log4J Vulnerability

  • September 15, 2026
  • 3 replies
  • 87 views

Leo Lin

Hi everyone,

Just a query, my company occasionally does sweeps on applications on end user devices to ensure there are no files within that are vulnerable to being attacked.

Recently they have marked Rocket MV Basic’s extension file, ls4b.jar as vulnerable, and want to know if this file is dependent on the application, and if there is a possibility to update this file, or if this file will be staying as it is?

Thank you.

Best answer by Doug Averch

Since Rocket Software embedded log4j in ls4b.jar you would have to know what version it is. If log4j is version 2.17 or less then it needs to be upgraded. See this link. The current version of log4j is 2.26. It should be noted that Rocket Software does not standardize it logging throughout it products, for example, xAdmin uses slf4j or logback call all be problematic if you do not keep up on upgrades.

3 replies

Christian Bristow
Forum|alt.badge.img+2

Hello Leo,

The  ls4b.jar is the MVVS language server and the extension is dependent on it. What’s the vulnerability being highlighted? 


Doug Averch
Forum|alt.badge.img+2
  • Inspiring
  • Answer
  • September 15, 2026

Since Rocket Software embedded log4j in ls4b.jar you would have to know what version it is. If log4j is version 2.17 or less then it needs to be upgraded. See this link. The current version of log4j is 2.26. It should be noted that Rocket Software does not standardize it logging throughout it products, for example, xAdmin uses slf4j or logback call all be problematic if you do not keep up on upgrades.


Christian Bristow
Forum|alt.badge.img+2

Thank you, engineering will review this (Rocket reference MVVS-1859)