Database Security Products (MOSC)

MOSC Banner

log4j oracle 12c(12.2.0.1) database vulnerability discovery CVE-2021-44228

I have been doing more research on the log4j vulnerability and finding out that the current oracle version 12.2.0.1 in use where I am has the log4j vulnerability even though oracle has stated the databases do not require patches. ( Oracle corp. defense they did not specify any version but was a generic statement)

This vulnerable log4j jar file is installed in all the oracle 12c (12.2.0.1) home

$ORACLE_HOME/md/jlib/log4j-core-2.9.1.jar

Can this jar file be upgraded/updated as a standalone and if so how?

If not, how would one mitigate the vulnerability CVE-2021-44228 in oracle 12.2.0.1 rdbms

Tagged:

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center