Does patch 8.58.17 include mitigation steps for CVE-2021-44228 and CVE-2021-45046 ?
Hello,
Doc ID 2828073.1 contains mitigation steps for CVE-2021-44228 and CVE-2021-45046 for log4j.
Do the log4j-core*.jar files delivered with Patch 8.58.17 are already updated (no JndiLookup.class class file in the log4j-core*.jar located in PS_HOME)?
Do the log4j-core*.jar files created when deploying PIA with Patch 8.58.17 are already updated (no JndiLookup.class class file in the log4j-core*.jar located in PS_CFG_HOME/webserv).
I reviewed the January 2022 Crital Patch Update report but above CVE are only listed for WebLogic, not for PeopleTools.
Thank you,
Best Regards,
Hervé