Missing patch in audit scan but the latest patches are already applied.
My question is if the July - 2019 patches are already applied why the scan is still asking for July -2018 OJVM patch.
I know to apply July -2019 BP I had to rollback July -2018 OJVM patch .. But latest should include previous ones.
I have already applied July - 2019 patches below on my Oracle 12cR1 on windows platform.
Windows Bunde Patch: p29831650_121020_MSWIN-x86-64
OJVM: p29837393_121020_MSWIN-x86-64
After patch when the audit team, scanned the system and found the below patch (July - 2018) missing from Oracle and throwing the vulnerability.
Vulnerabilities 10.13.11.138
111680 - Oracle Database Server CVE-2018-3110
-
Synopsis
The remote database server may be affected by CVE-2018-3110.