If customer does not wish to upgrade the existing version to latest version of OS and application then we would need to proceed as discussed earlier.
The engineering will investigate based on the scan report provided by the vulnerability scan engine on the ESM server and not based on the list of vulnerabilities received from any link as the list may contain 1000s of entries.
You also need to provide the details requested on the Questionnair I have already shared with you and this information is a must. Only then support could log a new case with engineering for further investigation.