Tom:
We have numerous Log4j on our server, not just Crystal reports.
As I understand it, in order to exploit the vulnerability a hacker would need to access your server from the internet using either Web services or Java. Make sure that anything someone can run from your website to access your server is patched.
This doesn't apply to Microsoft's RDP.