Our ISO is still complaining that our Horizon servers are vulnerable, according to Tenable. It's detecting log4j-core-2.16.0.jar, which indeed exists in path C:\Program Files\VMware\VMware View\Server\messagebus\kernel\sys$authentication on our fully patched connection servers. Can someone explain how exactly this build mitigates the threat? A pointer to an official doc from VMWare would be the best source, but I've yet to stumble across it.