Can CVE identified jar files be renamed or removed safely without any side effects?
RE: Critical 0-Day Vulnerability CVE-2021-44228
Oracle Enterprise Database 12.2.
According to the CVE response, the Oracle Database does not need to be patched. However the files are still present. Can they be renamed or removed without any harm to the installation?
/u01/app/oracle/product/12.2.0/dbhome_1/md/jlib/log4j-api-2.9.1.jar
/u01/app/oracle/product/12.2.0/dbhome_1/md/jlib/log4j-core-2.9.1.jar