I was under the impression that ArcGIS Enterprise 10.8.1 did not the vulnerable versions of log4j. This assumption was based off the early mitigation steps from Esri recommending an upgrade to 10.8 or higher (this was the recommendation (posted around 12/13/2021) before the mitigation scripts were released.
https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/arcgis-software-and-cve-2021-44228-aka-log4shell-aka-logjam/
But I see that the mitigation scripts are recommended after an upgrade for all versions.
"After upgrading Enterprise do I need to re-run the script again (for example, 10.9 to 10.9.1)
https://support.esri.com/en/technical-article/000026995
After doing an upgrade to 10.8.1 in our dev environment we reran the scripts and it removed a number of new log4j files.
Do all versions of ArcGIS Enterprise have the vulnerability? Therefore, an upgrade just reinstalls the vulnerable code?