H2 Vulnerability False Positive
Overview
Some project distributions of Bloomreach Experience Manager (brXM) include H2 Database libraries that are not used in production. Security scans may report vulnerabilities related to these unused libraries.
When This Occurs
This situation applies when you generate a brXM project distribution for production deployment. The distribution may contain H2 Database libraries, even though H2 is not supported or used in production environments.
Details
Bloomreach Experience Manager includes the H2 Database to support local development environments. H2 allows developers to set up and run brXM locally without additional database configuration. When you create a project distribution for production deployment, some H2 libraries remain packaged in the distribution.
These H2 libraries are not used or referenced by brXM in production. They are present only because they are part of the default development setup. In production, brXM does not initialize, expose, or interact with the H2 Database.
Security Scan Results
When you scan your brXM project distribution for known vulnerabilities, you may see vulnerability reports related to H2. These reports are false positives. The H2 libraries are present in the distribution but are never loaded or executed in production.
You can safely ignore vulnerability reports related to H2 in this context.
Additional Information
If you have questions or need further clarification, contact your Bloomreach support representative.