Issues with FR after applying Log4j fix
In this document, updated yesterday:
Apache Log4j Security Alert CVE-2021-44228 also referencing CVE-2021-45046 Mitigation on Oracle Enterprise Performance Management ( Doc ID 2828262.1 )
The instructions state to remove the .class files in the following 2.3.jar file for Financial Reporting:
- <MIDDLEWARE_HOME>\EPMSystem11R1\products\financialreporting\lib\log4j-core-2.3.jar
However, the main alert document states that 2.3 versions are not impacted:
Impact of December 2021 Apache Log4j Vulnerabilities on Oracle Products and Services (CVE-2021-44228, CVE-2021-45046) ( Doc ID 2827611.1 )
- Apache reported that CVE-2021-44228 applies only to Log4j versions 2.0-2.14.1, and does not apply to Log4j versions 1.x.