Hey,
we have a lot of different applications running as JAR files. The mitigations itself works, but why are the according metaf infos, like MANIFEST etc. not touched as well?
E.g. vulnerability scanners like tenable will detect these files still as vulnerable even though logpresso fixed the issue by deleting vulnerable classes from the JAR file.
BR