H2 Vulnerability False Positive

Overview

Some project distributions of Bloomreach Experience Manager (brXM) include H2 Database libraries that are not used in production. Security scans may report vulnerabilities related to these unused libraries.

When This Occurs

This situation applies when you generate a brXM project distribution for production deployment. The distribution may contain H2 Database libraries, even though H2 is not supported or used in production environments.

Details

Bloomreach Experience Manager includes the H2 Database to support local development environments. H2 allows developers to set up and run brXM locally without additional database configuration. When you create a project distribution for production deployment, some H2 libraries remain packaged in the distribution.

These H2 libraries are not used or referenced by brXM in production. They are present only because they are part of the default development setup. In production, brXM does not initialize, expose, or interact with the H2 Database.

Security Scan Results

When you scan your brXM project distribution for known vulnerabilities, you may see vulnerability reports related to H2. These reports are false positives. The H2 libraries are present in the distribution but are never loaded or executed in production.

You can safely ignore vulnerability reports related to H2 in this context.

Additional Information

If you have questions or need further clarification, contact your Bloomreach support representative.

Share Feedback
Page: /deploy/security-logging/h2-vulnerability-false-positive
Section: Deploy
Category *
H2 Vulnerability False Positive | Bloomreach Content Documentation