Apache Log4j vulnerability CVE-2021-44228 is probably impacting the Oracle Database
Hi All,
I have this question, as per oracle note Apache Log4j Security Alert CVE-2021-44228 Products and Versions (Doc ID 2827611.1) Oracle Database is not impacted by this vulnerability.
But once I did more on Oracle Database Home I have found that there are components like TFA is using LOG4J.
./suptools/tfa/release/tfa_home/jlib/log4j-api-2.9.1.jar
./suptools/tfa/release/tfa_home/jlib/log4j-core-2.9.1.jar
Does anybody have any idea about this. I know we can upgrade the TFA but need to know which version is better and is there any other approach.