# Nexus IQ remediation and JBOSS

**URL:** <https://community.sonatype.com/t/nexus-iq-remediation-and-jboss/5405>\
**Category:** Sonatype Lifecycle & Firewall\
**Created:** [November 19, 2020, 3:00pm UTC](https://community.sonatype.com/t/nexus-iq-remediation-and-jboss/5405 "2020-11-19T15:00:13Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![bogartlisa](https://avatars.discourse-cdn.com/v4/letter/b/a88e4f/32.png) [@bogartlisa](https://community.sonatype.com/u/bogartlisa)\
**Post date:** [November 19, 2020, 3:00pm UTC](https://community.sonatype.com/t/nexus-iq-remediation-and-jboss/5405/1 "2020-11-19T15:00:13Z")

</div>

Hi,

I am kind of new to Nexus IQ. We have a number of java apps running on Redhat Jboss EAP severs. Quite a number of the violations picked up by Nexus IQ are transitive dependencies supplied by the app server. Remediating those by upping the version is kind of a snake pit. Does anyone have a suggested path or pattern for dealing with these? Example:  
com.fasterxml.jackson.core : jackson-databind : 2.5.4 is flagged as Security-Critical. Swapping this out to a violation free version 2.11.0 is not a simple matter. How do folks deal with this? Waivers? Overriding the dependencies provided by JBOSS?? If I am in the wrong place, please let me know.
