We currently have ArcGIS 10.9 deployed and the vulnerability CVE-2016-1000027 is showing up in our security scans. It looks like all Spring Framework versions prior to 6.x.x have this vulnerability.
Do newer versions of Enterprise (11 or 11.1) use Spring 6.x.x, or is it still a 5.x.x version? If it still uses the 5.x.x version, is ArcGIS Enterprise actually affected by this vulnerability? Thanks.