Bloomreach Experience Manager 15.1.3
This maintenance release updates several dependencies that are related to the recently publicized "text4shell" vulnerability, CVE-2022-42889. Bloomreach has confirmed that the brXM product is not vulnerable, but we cannot rule out that customer code using this library may be. As a rapid-response precaution, we have updated the version of Apache Commons Text used by our product to 1.10.0, which operates in a safer way by default.
https://xmdocumentation.bloomreach.com/about/release-notes/15/15.1.3-release-notes.html