CVE-2021-44832 requires log4j version 2.17.1. When will AHF be updated with that log4j version?
AHF 21.4 was released in response to CVE-2021-44228. We have AHF installed in /opt as root for Oracle Database 12.1 running on AIX 7.2. Any AHF updated version is usually part of the quarterly CPU grid patch. I am aware that 12.1 is EOF. Does Oracle consider this configuration vulnerable under CVE-2021-44832? If so, will AHF be updated as part of the upcoming January 2022 CPU or earlier?
Thanks, Peter