Database Utilities (MOSC)

MOSC Banner

Apache Log4j vulnerability CVE-2021-44228 is probably impacting the Oracle Database

Hi All,

I have this question, as per oracle note Apache Log4j Security Alert CVE-2021-44228 Products and Versions (Doc ID 2827611.1) Oracle Database is not impacted by this vulnerability.

But once I did more on Oracle Database Home I have found that there are components like TFA is using LOG4J.

./suptools/tfa/release/tfa_home/jlib/log4j-api-2.9.1.jar

./suptools/tfa/release/tfa_home/jlib/log4j-core-2.9.1.jar

Does anybody have any idea about this. I know we can upgrade the TFA but need to know which version is better and is there any other approach.

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center