log4j oracle 12c(12.2.0.1) database vulnerability discovery CVE-2021-44228
I have been doing more research on the log4j vulnerability and finding out that the current oracle version 12.2.0.1 in use where I am has the log4j vulnerability even though oracle has stated the databases do not require patches. ( Oracle corp. defense they did not specify any version but was a generic statement)
This vulnerable log4j jar file is installed in all the oracle 12c (12.2.0.1) home
$ORACLE_HOME/md/jlib/log4j-core-2.9.1.jar
Can this jar file be upgraded/updated as a standalone and if so how?
If not, how would one mitigate the vulnerability CVE-2021-44228 in oracle 12.2.0.1 rdbms