Oracle Configuration Manager 12.1.2.0.6 patch fix for CVE-2017-5645 (Not able find this Release of O
Reviewing Critical Patch Update Oct 2018 Patch Availability DocID 2433477.1 for Oracle Enterprise Manager critical vulnerabilities ...one being for Oracle Configuration Manager. The doc states that Oracle Configuration Manager Release 12.1.2.0.6 is to be used to address CVE-2017=5645. However, I'm not to find this release of OCM. Latest I'm finding is OCM 12.1.2.0.4. Also, I've disabled OCM ...meaning Oracle Configuration Manger is not running. Not able to determine if this is sufficient to mitigate the CVE or if one must still patch/upgrade OCM.
The "Oracle Critical Patch Update Advisory - October 2018" document, for Enterprise Manager Base Platform, versions 12.1.0.5, and 13.2 ...indicates the Supported Versions Affected of OCM are 12.1.2.0.2, 12.1.2.0.5 related CVE-2017-5645, our OCM version is 12.1.2.0.4 ...strange the gap between 12.1.2.0.2 to 12.1.2.0.5 (are we affected running on 12.1.2.0.4 OCM?)